91 lines
No EOL
3.2 KiB
Nix
91 lines
No EOL
3.2 KiB
Nix
let
|
|
admin = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIK6DjXTAxesXpQ65l659iAjzEb6VpRaWKSg4AXxifPw9 Skynet Admin";
|
|
silver_laptop_wsl = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEHNLroAjCVR9Tx382cqdxPZ5KY32r/yoQH1mgsYNqpm Silver_Laptop_WSL_Deb";
|
|
thenobrainer ="ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKjaKI97NY7bki07kxAvo95196NXCaMvI1Dx7dMW05Q1 thenobrainer";
|
|
|
|
users = [
|
|
admin
|
|
silver_laptop_wsl
|
|
thenobrainer
|
|
];
|
|
|
|
# change this when its properly set up
|
|
agentjones = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAbqYQrdVHmGgXZJoMWWRDGVEIj775Zrf4PxB5hoth+k root@agentjones";
|
|
ash = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGJDVQGjIwMQmkElGshgKDAlChM2xdNN6iI5Ap2IbAs5";
|
|
# dns servers
|
|
vendetta = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINxTrUPZPqttuxfmmP8BTACTAkv1yY1nfzEd64hN4LT+ root@vendetta";
|
|
vigil = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICDsz1bjNAThqwF48dKIJGOECsCKHTj/Gn5Gh9XyzoSO root@vigil";
|
|
|
|
galatea = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAII3Mke5YtaMkLvXJxJ3y7YAIEBesoJk3qJyJsnoLUWgW root@galatea";
|
|
|
|
# for testing configs at home
|
|
silver_homelab = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCG1JzosOwS7oKjgm0+FlqMKrUbu+M5403un+VA7LwiGRQnneawuq6aqQsIoDqAlb9AzUdLTeBQb+rBf94kx7yVGdEIz1i34WdMK3kgl176jnDIR4TWeNKdj8Q6+4d7tn5mZrqmpXZ/+1KSauV9JHxytR+7A4NVexkhGX1Mq3efGBYsCKzUQh83lHs2baWUYuxaPCCR6vy6uklzQRQfg+NsxCCUKkbgJwv1ar5U1ccr4N89EWiR2Yu4XsPzXr0JJUQcUy587l+G7QYVoCwVgUKHevCRqtRlmnI6JrzWctQJPpAmWF4EF66QnWccdXUS+aVc0IKP0ORqmz8Nps4NWWVPjRRxeshl2XfFawWxGlgT4WJ0+qv/EDVPZQvNBrjFvY5QBAaU08Nnkg6QzehlwD4/zQQMFiDjMb7sUuhXdq0vOK235QMhS4jtX7Sm2ki6mJdXrlErq9dIaqcoYuw9EtfajaM/NnGYIy97JUOrfztQTAwiuPgrc4DijpdR0QtvYK7NvefiJYcW+osmcv+FYM03kMXK9uGtM6KI44i27ZdsUFWTIHeiR1yBGUfP1ObFLLaNx5E42jSA77RLF8BSUaPbGgRv3OciACNftIKhAJrV4AZGvBbaUvAlzC8CryFAcRDgQwIVlXBJzChc7Rh9/V8I5342Tq7xMmzBQ2WcQdqZ9Q== root@galatea";
|
|
|
|
optimus = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIqYbbWy3WWtxvD96Hx+RfTx7fJPPirIEa5bOvUILi9r root@optimus";
|
|
|
|
glados = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJ6go7ScvOga9vYqC5HglPfh2Nu8wQTpEKpvIZuMAZom root@glados";
|
|
|
|
kitt = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPble6JA2O/Wwv0Fztl/kiV0qj+QMjS+jTTj1Sz8k9xK root@kitt";
|
|
|
|
gir = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINL2qk/e0QBqpTQ2xDjF7Cv4c92jJ53jW2fuu88hAF/u root@gir";
|
|
|
|
systems = [
|
|
agentjones
|
|
ash
|
|
|
|
silver_homelab
|
|
];
|
|
|
|
dns = [
|
|
vendetta
|
|
vigil
|
|
];
|
|
|
|
email = [
|
|
gir
|
|
];
|
|
|
|
ldap = [
|
|
kitt
|
|
]
|
|
++ gitlab
|
|
++ email;
|
|
|
|
gitlab = [
|
|
glados
|
|
];
|
|
|
|
# these need dns stuff
|
|
webservers = [
|
|
# ULFM
|
|
galatea
|
|
# Games
|
|
optimus
|
|
]
|
|
# ldap servers are web facing
|
|
++ ldap
|
|
++ gitlab;
|
|
|
|
in
|
|
{
|
|
# nix run github:ryantm/agenix -- -e secret1.age
|
|
|
|
"dns_certs.secret.age".publicKeys = users ++ webservers;
|
|
"dns_dnskeys.conf.age".publicKeys = users ++ dns;
|
|
|
|
"stream_ulfm.age".publicKeys = users ++ [galatea];
|
|
|
|
|
|
"gitlab/pw.age".publicKeys = users ++ gitlab;
|
|
"gitlab/db_pw.age".publicKeys = users ++ gitlab;
|
|
"gitlab/secrets_db.age".publicKeys = users ++ gitlab;
|
|
"gitlab/secrets_secret.age".publicKeys = users ++ gitlab;
|
|
"gitlab/secrets_otp.age".publicKeys = users ++ gitlab;
|
|
"gitlab/secrets_jws.age".publicKeys = users ++ gitlab;
|
|
"gitlab/ldap_pw.age".publicKeys = users ++ gitlab;
|
|
|
|
# for ldap
|
|
"ldap/pw.age".publicKeys = users ++ ldap;
|
|
"ldap/self_service.age".publicKeys = users ++ ldap;
|
|
|
|
} |