secrets: reorganised it so it makes more sense who has access to what secrets
This commit is contained in:
parent
81afc614a3
commit
f39934a437
4 changed files with 16 additions and 6 deletions
Binary file not shown.
Binary file not shown.
|
@ -21,23 +21,33 @@ let
|
|||
# for testing configs at home
|
||||
silver_homelab = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCG1JzosOwS7oKjgm0+FlqMKrUbu+M5403un+VA7LwiGRQnneawuq6aqQsIoDqAlb9AzUdLTeBQb+rBf94kx7yVGdEIz1i34WdMK3kgl176jnDIR4TWeNKdj8Q6+4d7tn5mZrqmpXZ/+1KSauV9JHxytR+7A4NVexkhGX1Mq3efGBYsCKzUQh83lHs2baWUYuxaPCCR6vy6uklzQRQfg+NsxCCUKkbgJwv1ar5U1ccr4N89EWiR2Yu4XsPzXr0JJUQcUy587l+G7QYVoCwVgUKHevCRqtRlmnI6JrzWctQJPpAmWF4EF66QnWccdXUS+aVc0IKP0ORqmz8Nps4NWWVPjRRxeshl2XfFawWxGlgT4WJ0+qv/EDVPZQvNBrjFvY5QBAaU08Nnkg6QzehlwD4/zQQMFiDjMb7sUuhXdq0vOK235QMhS4jtX7Sm2ki6mJdXrlErq9dIaqcoYuw9EtfajaM/NnGYIy97JUOrfztQTAwiuPgrc4DijpdR0QtvYK7NvefiJYcW+osmcv+FYM03kMXK9uGtM6KI44i27ZdsUFWTIHeiR1yBGUfP1ObFLLaNx5E42jSA77RLF8BSUaPbGgRv3OciACNftIKhAJrV4AZGvBbaUvAlzC8CryFAcRDgQwIVlXBJzChc7Rh9/V8I5342Tq7xMmzBQ2WcQdqZ9Q== root@galatea";
|
||||
|
||||
optimus = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIqYbbWy3WWtxvD96Hx+RfTx7fJPPirIEa5bOvUILi9r root@optimus";
|
||||
|
||||
systems = [
|
||||
agentjones
|
||||
ash
|
||||
galatea
|
||||
vendetta
|
||||
vigil
|
||||
|
||||
silver_homelab
|
||||
];
|
||||
|
||||
dns = [
|
||||
vendetta
|
||||
vigil
|
||||
];
|
||||
|
||||
# these need dns stuff
|
||||
webservers = [
|
||||
galatea
|
||||
optimus
|
||||
];
|
||||
|
||||
in
|
||||
{
|
||||
# nix run github:ryantm/agenix -- -e secret1.age
|
||||
|
||||
"dns_certs.secret.age".publicKeys = users ++ systems;
|
||||
"dns_dnskeys.conf.age".publicKeys = users ++ systems;
|
||||
"dns_certs.secret.age".publicKeys = users ++ webservers;
|
||||
"dns_dnskeys.conf.age".publicKeys = users ++ dns;
|
||||
|
||||
"stream_ulfm.age".publicKeys = users ++ systems;
|
||||
"stream_ulfm.age".publicKeys = users ++ [galatea];
|
||||
|
||||
}
|
Binary file not shown.
Loading…
Reference in a new issue