nixos/secrets/secrets.nix

117 lines
3.2 KiB
Nix
Raw Permalink Normal View History

2023-01-25 11:48:44 +00:00
let
admin = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIK6DjXTAxesXpQ65l659iAjzEb6VpRaWKSg4AXxifPw9 Skynet Admin";
silver_laptop_wsl = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEHNLroAjCVR9Tx382cqdxPZ5KY32r/yoQH1mgsYNqpm Silver_Laptop_WSL_Deb";
thenobrainer ="ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKjaKI97NY7bki07kxAvo95196NXCaMvI1Dx7dMW05Q1 thenobrainer";
2023-01-25 11:48:44 +00:00
users = [
admin
silver_laptop_wsl
thenobrainer
2023-01-25 11:48:44 +00:00
];
# change this when its properly set up
agentjones = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAbqYQrdVHmGgXZJoMWWRDGVEIj775Zrf4PxB5hoth+k root@agentjones";
2023-01-25 11:48:44 +00:00
ash = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGJDVQGjIwMQmkElGshgKDAlChM2xdNN6iI5Ap2IbAs5";
# dns servers
vendetta = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINxTrUPZPqttuxfmmP8BTACTAkv1yY1nfzEd64hN4LT+ root@vendetta";
vigil = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICDsz1bjNAThqwF48dKIJGOECsCKHTj/Gn5Gh9XyzoSO root@vigil";
2023-04-20 18:21:28 +00:00
galatea = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAII3Mke5YtaMkLvXJxJ3y7YAIEBesoJk3qJyJsnoLUWgW root@galatea";
optimus = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIqYbbWy3WWtxvD96Hx+RfTx7fJPPirIEa5bOvUILi9r root@optimus";
2023-04-20 18:21:28 +00:00
2023-06-15 01:47:56 +00:00
glados = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJ6go7ScvOga9vYqC5HglPfh2Nu8wQTpEKpvIZuMAZom root@glados";
2023-06-17 18:37:06 +00:00
wheatly = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEehcrWqZbTr4+do1ONE9Il/SayP0xXMvhozm845tonN root@wheatly";
2023-05-16 22:18:40 +00:00
kitt = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPble6JA2O/Wwv0Fztl/kiV0qj+QMjS+jTTj1Sz8k9xK root@kitt";
gir = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINL2qk/e0QBqpTQ2xDjF7Cv4c92jJ53jW2fuu88hAF/u root@gir";
neuromancer = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID7NRDOGzSO4XVEezMS/9pI3chKbOH0fw2aikLRvea2P root@neuromancer";
2023-07-20 21:42:01 +00:00
skynet = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAIFPXJswth8H1k8+zrg8vCnPkfG1hIIa3wR9DBmjpB5 root@skynet";
2023-01-25 11:48:44 +00:00
systems = [
agentjones
ash
vendetta
vigil
galatea
optimus
glados
wheatly
kitt
gir
neuromancer
2023-07-20 21:42:01 +00:00
skynet
];
dns = [
vendetta
vigil
];
2023-04-23 03:22:01 +00:00
email = [
gir
];
ldap = [
kitt
]
++ gitlab
++ email;
2023-06-15 01:47:56 +00:00
gitlab = [
glados
];
2023-06-17 18:37:06 +00:00
gitlab_runners = [
wheatly
];
# these need dns stuff
webservers = [
# ULFM
galatea
# Games
optimus
2023-07-20 21:42:01 +00:00
# skynet is a webserver
skynet
]
# ldap servers are web facing
2023-06-15 01:47:56 +00:00
++ ldap
++ gitlab;
2023-05-24 19:57:49 +00:00
restic = [
neuromancer
];
2023-01-25 11:48:44 +00:00
in
{
# nix run github:ryantm/agenix -- -e secret1.age
"dns_certs.secret.age".publicKeys = users ++ webservers;
"dns_dnskeys.conf.age".publicKeys = users ++ dns;
2023-04-21 00:44:11 +00:00
"stream_ulfm.age".publicKeys = users ++ [galatea];
2023-04-21 00:44:11 +00:00
2023-05-16 15:40:49 +00:00
2023-06-15 01:47:56 +00:00
"gitlab/pw.age".publicKeys = users ++ gitlab;
"gitlab/db_pw.age".publicKeys = users ++ gitlab;
"gitlab/secrets_db.age".publicKeys = users ++ gitlab;
"gitlab/secrets_secret.age".publicKeys = users ++ gitlab;
"gitlab/secrets_otp.age".publicKeys = users ++ gitlab;
"gitlab/secrets_jws.age".publicKeys = users ++ gitlab;
"gitlab/ldap_pw.age".publicKeys = users ++ gitlab;
2023-05-16 15:40:49 +00:00
2023-06-17 18:37:06 +00:00
"gitlab/runners/runner01.age".publicKeys = users ++ gitlab_runners;
# for ldap
"ldap/pw.age".publicKeys = users ++ ldap;
"ldap/self_service.age".publicKeys = users ++ ldap;
# everyone has access to this
"backup/restic.age".publicKeys = users ++ systems;
"backup/restic_pw.age".publicKeys = users ++ restic;
2023-01-15 22:20:55 +00:00
}