From c360bfe68b56e4eb9eb0971cb4398c70937f7486 Mon Sep 17 00:00:00 2001 From: Alexander Heldt Date: Sat, 31 Aug 2024 11:53:59 +0200 Subject: [PATCH] backwards: Add secrets for `syncthing` --- hosts/backwards/modules/syncthing/default.nix | 12 +++++++++++- secrets/backwards/syncthing-cert.age | Bin 0 -> 1115 bytes secrets/backwards/syncthing-key.age | Bin 0 -> 609 bytes secrets/secrets.nix | 2 ++ 4 files changed, 13 insertions(+), 1 deletion(-) create mode 100644 secrets/backwards/syncthing-cert.age create mode 100644 secrets/backwards/syncthing-key.age diff --git a/hosts/backwards/modules/syncthing/default.nix b/hosts/backwards/modules/syncthing/default.nix index 177406c..8dbbb58 100644 --- a/hosts/backwards/modules/syncthing/default.nix +++ b/hosts/backwards/modules/syncthing/default.nix @@ -1,12 +1,22 @@ -{ ... }: +{ config, ... }: { services.syncthing = { enable = true; openDefaultPorts = true; + cert = config.age.secrets.syncthing-cert.path; + key = config.age.secrets.syncthing-key.path; + user = "alex"; group = "users"; dataDir = "/home/alex/sync"; }; + + age = { + secrets = { + "syncthing-cert".file = ../../../../secrets/backwards/syncthing-cert.age; + "syncthing-key".file = ../../../../secrets/backwards/syncthing-key.age; + }; + }; } diff --git a/secrets/backwards/syncthing-cert.age b/secrets/backwards/syncthing-cert.age new file mode 100644 index 0000000000000000000000000000000000000000..2808be147c6dbb6cbf784281509e5c48d7d23179 GIT binary patch literal 1115 zcmYdHPt{G$OD?J`D9Oyv)5|YP*Do{V(zR14F3!+RO))YxHMCR+C^hg1PggMTjtue5 z@G>_Kamg%*$V@d&HBB-}%=F1ItI8=XFV8P7sdP&#_boKd3goKF4K1<=F!V3bE-*^e z4lMR_Dlbh=FE=qMDKQK)F|^3c&kk`jEY8bvk3_dkJKrzSBTyl-z{1im&B!~%E59Vq zIl!_aJWbytt0K=R&DF)R)YmW2IVa68yC@^j!-C7yFW4o@s7l)>(Z#VOFWlTT(K*1q zs-P?=$iS^ERNu(cv%)OVJGa2cz?Dl^S69J1!#S%Yv&b~f&(Jm4$RsDQ$|B7$#LV0v zu{_ObM$!d8bQ`sB6+4IE}xFpX^n8@{ivLK)8#*W|} zuY&@`vL*GI&)Gz$vhK4xIJJM}g1a)z`F}1PTpKIScreZ7+IK_aq`XYwO-vWB8sC?w zN}a8k>9H^O-rTaq_yvyi`hD2en8;o&EE@Dmg}yvV{zId|8wf~uPRftL>LU_ zay(lnY9~?}X`CI>;^llil=Y&~muqSVKA$<^`A6npQ2DGx(f_t8XI0KJyWN-jvq`cPP$0vgpzPH@dT|9WDec%IppJN&w~u8S?1 G3giH`{_Fq% literal 0 HcmV?d00001 diff --git a/secrets/backwards/syncthing-key.age b/secrets/backwards/syncthing-key.age new file mode 100644 index 0000000000000000000000000000000000000000..9b23e857cf0bbbc51645711d8a7d2fb4bc83a1f3 GIT binary patch literal 609 zcmYdHPt{G$OD?J`D9Oyv)5|YP*Do{V(zR14F3!+RO))YxHMCR+C^hg1PggK33oZ@G zDl#gM@(d{|aB&RD%gW4k_wjZOb~6w2G4m|;3^Dh}O3EwGGvLZ}GIunL%nmk7Pfn^b zuuO``Ne=g}Ob#qawn)iNuP83p_6i8f(GN2;4n((2JKrzSBTykAEvmpE#UiC5#k`=P zI5;RgSHC38A}A;)xHKdxxjZy0tEAj0#iuga(Uq&jteZ|BFDvTH`o+(@r>b9S?*Z6Q1ll%r}p@|P?E?Hdv_3$1y(|Ly#G{P8meyKh1$3=@T z`HgK^PV0A-qpI$A{xjJ!5 tSDe@hnVGRGR%F+zT?)$+@eb5e+j`G_OY!#hhvA1ZqNdkLxSQO(4FE3(@z?+W literal 0 HcmV?d00001 diff --git a/secrets/secrets.nix b/secrets/secrets.nix index bda13c2..db58d11 100644 --- a/secrets/secrets.nix +++ b/secrets/secrets.nix @@ -31,6 +31,8 @@ in { "backwards/root.backwards.age".publicKeys = [ backwards alex ]; "backwards/root.backwards.pub.age".publicKeys = [ backwards alex ]; + "backwards/syncthing-cert.age".publicKeys = [ backwards alex ]; + "backwards/syncthing-key.age".publicKeys = [ backwards alex ]; "backwards/alex.backwards-codeberg.org.age".publicKeys = [ backwards alex ]; "backwards/alex.backwards-codeberg.org.pub.age".publicKeys = [ backwards alex ]; "backwards/wpa_supplicant.conf.age".publicKeys = [ backwards alex ];