From 87a9d94d0a0c2710ba84a54e014f812b73c5a75b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Benjamin=20B=C3=A4dorf?= Date: Sat, 23 Oct 2021 13:24:22 +0200 Subject: [PATCH] secrets via agenix --- hosts/chocolatebar/base.nix | 2 +- modules/devops/default.nix | 1 + modules/x-os/boot.nix | 5 +++-- secrets/keyfile-biolimo.bin | Bin 0 -> 4832 bytes secrets/keyfile-chocolatebar.bin | Bin 0 -> 4810 bytes secrets/secrets.nix | 37 +++++++++++++++++++++++++++---- 6 files changed, 38 insertions(+), 7 deletions(-) create mode 100644 secrets/keyfile-biolimo.bin create mode 100644 secrets/keyfile-chocolatebar.bin diff --git a/hosts/chocolatebar/base.nix b/hosts/chocolatebar/base.nix index 76175878..10de4abb 100644 --- a/hosts/chocolatebar/base.nix +++ b/hosts/chocolatebar/base.nix @@ -11,7 +11,7 @@ in ]; config = { - pub-solar.x-os.keyfile = "/etc/nixos/hosts/chocolatebar/secrets/keyfile.bin"; + pub-solar.x-os.keyfile = "keyfile-chocolatebar.bin"; pub-solar.virtualisation.isolateGPU = "rx550x"; diff --git a/modules/devops/default.nix b/modules/devops/default.nix index eadac960..ab81c57f 100644 --- a/modules/devops/default.nix +++ b/modules/devops/default.nix @@ -12,6 +12,7 @@ in config = mkIf cfg.enable { home-manager = with pkgs; pkgs.lib.setAttrByPath [ "users" psCfg.user.name ] { home.packages = [ + croc drone-cli nmap python38Packages.ansible diff --git a/modules/x-os/boot.nix b/modules/x-os/boot.nix index 5068590e..176d9d4f 100644 --- a/modules/x-os/boot.nix +++ b/modules/x-os/boot.nix @@ -1,4 +1,4 @@ -{ config, pkgs, lib, ... }: +{ config, pkgs, lib, self, ... }: let cfg = config.pub-solar.x-os; @@ -17,8 +17,9 @@ with lib; { # Use Keyfile to unlock the root partition to avoid keying in twice. # Allow fstrim to work on it. + age.secrets.luksKeyFile.file = "${self}/secrets/${cfg.keyfile}"; boot.initrd = { - secrets = { "/keyfile.bin" = cfg.keyfile; }; + secrets = { "/keyfile.bin" = "/run/secrets/${cfg.keyfile}"; }; luks.devices."cryptroot" = { keyFile = "/keyfile.bin"; allowDiscards = true; diff --git a/secrets/keyfile-biolimo.bin b/secrets/keyfile-biolimo.bin new file mode 100644 index 0000000000000000000000000000000000000000..4fb697238b1b796b4386e0ea4081854a8fb03868 GIT binary patch literal 4832 zcmXxkg;$gbpapQSkU<3t#aO{LkP)WKK&SJYo?&K?nC>2?#8^dS5d=Ze1uR4m!B_)j zRX|X|E>sk-15sE6YmMdYd*{5r;GT2O?_Rl99jmq|9X^{&Z?(i(9a@MR28xZ3bUJmh z4yQcQNFfQJco0BWqv32D1xeD;eIy>kDF=K6of<9FsaQ4xo@Am>P*RD&D+1fGfW~FV zIN<^Tg<#cs5d<0AO#)dJE|bEENsu%AXeXHHfhI`7ZYB<(!hJfG1gB8TjRrPZXvOF` zP@#rt@oOwLDOn)~C~yadNQQw7bTB#r(9pnGgN6#Hd3<;w-cO^7=>P-|OYmBFGBsSw zkXcZ672Hk2`v5BmWwDvrUb2nia53Q^1K{Y;skOoVj%k)$=(+~KFIG7zFaj;|xp2DE^ z8r=ks!EE;7z(kZUfeZ-9OpjcJBNByfoLmXGh$uuIo}-XRU1+*WfhL>OOtwlTVymeT4~0h8^G#_A3mT-f@yG^+5g^l?LNeD% zCx|6hE`f{nlF3BB-Api(AWo^*r17%d8X6sfWn)B0GSnvo99+K2nuZ18xneSeYo$;D z1rMusfE9oZ<5Su!IKEPc^)e`Ui9p0~hzWdx1mPD#Sd=s}LBvp{fh{5=-a?{*h%hAs ztmcv^IFC4uP0@JqHaXE`bL;I?mWz+3X^}Jn&dl?o)g)?~n1-N>9WEu7>ac2bt^|Zu z2f~w#COtt!l;foinS}45Kov{`(n8ZJ30!!Z(@#_D_*e#u!PQGtRy~eDqbOZ8C>oGs z=uDZ@i3Ty4G_zbtVky8*4Z?wetF?4GUaVl_WMn#1V<3|JST`8UMC-7||97lb!BHp} zE>dU_BrtiAK0E?$VXH-A5{hMkOC7!eE%AC9Df_(U0s zz<7N@3T zKu|eUhG2U9Y}kK<%{UX;!^A=e2DeFwg<***rWDUaI~;l#m#qM}T!4fl8No)3QSKs0 zp;9$Q1wy(N1{OKNKqQl>Ca8u=fYOO9w9k$eTFojbBLPBEdwf)bOKtJUtO*Q=8KaWJ zB^IHYXjc(65G07B6JcRE8V)QKKrnVTHjT-bn2ap81?whYkw}e~BU2bH2BuEV_3*HA zl9~X8%lv4Mm+H5peSjTgNT2~}b|nIXgVB@{o=z@>8a!^7oaU48EIg-ytd?qh4!4j( zh6%V{H=0W}tHo?DK?CPlZF(pUWMSC|L@opE<5J0HrNWrzbu;K%Bb2Tbn;3Snn@!Y% zdGa(a51b&9TGE^rtVpO68-!Q}5>LYD^&prFA=FXbZXMS~A|?m`0p4x38mUr*iEA~n zNCaU5oB=5C8i>T93sntBc z!bQ=mjd-?R1m;n6b}yD|HhZufEf@v1xDap|k4+Qc5?CB76%XhIAST`*MB#K23JU;Z z{I&$RkioYY{ALQ;kVbI0@ItqiuVsV5QX%&L9H+%<9csB#9f^>+c_0~>4CuI26%Pi( zqNN-Go2Ky@DJ+Nw!&X>HW-=aZ@#1lMuNbPb3bZ_pK<5((xK^wIgLK%HFf52DWyo|Q z;J;IF8O=UPf|#Qgz-j+gXkic}9uFusHZ~Hk6d2t&5)6>&^jMFTm>1M4IiDN0DphX45q(euxCFW38t*w@u4jKGOmiPs0zc1j(>Y5cgp_uy>ytMfy`Qh#o=F>MhZV-zTfXG~4NbcI+Q2V3;oljd-dtzxDHj#e9f9PB ztCB;em>4ftjjHemcd9Q}-W>AZ*(wWwR#Ru>C9@y&XT;Qxtyi8}Gv&`cA(h9m;Xl41 z);&vpOEXkWdh^T9JV6IMlQ2JH;0=d*HtYSWEu-m;drR-VKPj4*C%tm{!SU>fm^I6z zz8O0En>SMmw?@_4_s=yQ`U-q~HuKHz&W_D@ZU!u1foDBAysJp_f`)E7EUBxPeaekK zcz5@j^tPJ$wT-ACdlne1&igg{TGQYWA0^4v#$*jQ<%(ZrPHr9wtQ^~r^&-vic+KlX zmG6e=1$S~l!Lcyk@cy4$pY9uHe$|AhUvEt$&AexwaFKhSHsNwn$78Im_nCWV%>3?4 zUAG=)#9e&%asAODbm{Rw`aNss1Jw)Xw=4Qfv3hb`7CZj#_vZb(qn5?j_X@|RN#->k zbnf~5^5p5ueaR)!EynlMKHp?X(kFc028VG`V76&V;PsfXoek6cAKlBJt|IJ-yYOS_ z7!>?(I&KoPyx@jOd#R*+={&9K2TotHVBAIl<=e7jwCRHA&fM&k`z!vIH#$T^6vDpf z+XscepA+o;IIvcD=w<7)Qx63Pz+YXrB2%vxeQJ><>|9+p-#gg! zA1WT~9QSp~s^>XRR^N&#k(YsrN4*FP>nvxiL!E*aM7PatsHhl5yfjJ>F=PGckvjqi z*Cq4EL2AC-1#<8}WS@5ZqMAST?lYaC>rLQSZfg5q3K)-b(S1wc^E8vWw+`V?G z=oV13XZ-fSa{8wU)FqgeU9E9fKOWi6-LYEpKCtTg9(~6rRaWwb)+{k@)k^D*pqbro zXLW>{jD=Aj)vX25egEL$A(R?fXm`dfx^n5HZ8sObo%8jtnbY+BvGB0#XCB0#DYqIE zg9Jr@y;Kq)ytr>aQ2TAij!I76-D?o7r*GbRwsc%4!s}bB|6wNNg?efKGgJ?!sTxk2@25;|=As zFyqF@<3N4Icfq!av%!<{>3Et#xV(k2_~)q}|B8eoia$}$U!0_ERc)HufXt)s|J+ad z;O*Z^s)^u#-YI^pf(C*2RnYdj&j!EoEi~i*TfC~N^zN=BP)+(k^w^+NiywEuvOaVC zn`SoUzC`8kUOa}oZ(lxRPRqPW$_>^Oy&gIuhw%7GSXb@vjds%P<81$*FNwE#i`r); z#vZ7?z8unX`T7X}8tVc-e`%JWHXf z8Gjbv7E#i%iFRohyiFcF*HvFL68_OsGsF+Af2wGlHq!KPLzzV?j89p%=g6K4%cZP7 z6Ql=U^@IBS?*q>}$ImBk-jsax;pN7N#{uEo+}zy7#-t-N`}@LSgclHvk~81ZA|6oIZM3{I~&y4hu z<@G^+Vv*`W%_V<+Y6UjAE4=ZWa)S(bUdH_qf8^YR@{}r&;(Et}c_WLS2Y#(n9=vOBYsF^1HVI>)PVWTIV-sj@g$uD|q7pGWY~HW%JZd28z7z z2KqpTq7r>3A~O^kx~UUg7{lksE(ZADO(zYA>a2ff?w@+PrfSpDp6)w6j>Nj@-(OQc z+02vTo|haf7rbvsi?g?1`LuWPex-cwj@v7y(oRf`yOQ~39Qs-+Iv}*&+(0N4gaMxzO3n{ zl1XW2_k372DpmZWf)O}S$Yx7q50sCX-?y)ynYhOhr1|xE74?PIbnXfJ`~t!We<5G| zwymnVW1wLBsl7l(z^3W*|5)s1j(sq3=}|MxeYP~bEBC|bmaX8%N@w{Sa?LGK7C`ik zlh>~CwmcZT#?I)y`t)H_I8X6M&CDq&nS;m;6c>8bJGbPomu;z=9l^U6`Wr+lsi+Ey*LEFuOZ8F8dc~#wDTZDx%V7MO3XANwAhpy}dX3^ejIy|Kd4m z^~mCp;qhPK*Rq~nPaig*KDk?7#?U+4?nyFAo_GR1q1p1SZ~u)7e}Dhp$kH-0KI7zJ z$s(e(9WYiwEsmF8I(tJtWJD#2zibZ5`aGh9USHDKNW`5ESRH)S|JkVwF_mu$bE^`9 z5+~W=yfFyT4u-DNSyH0jCPx%8mAn7#{?g5%pm$bqe`~Lh zooZe>9b;PZDqjqEB8Q5Y2Q@eE^zb7^QRXAa@m@m1wAEie9ca~s`9rUNST%9h+6jyC zjf|eGt%9+d#;z|ZUj|#h{GK8`f>{+9u72`(;6qaN<&=b>r^?AN@YW4a_L3xYtt~wc>1K zz#7@$)0oF$M0|o#!q}eTV*me z+r?uSJv>i&@6CL-sMs0XxbN`UCG?f#d%aO96eM!e>Oo;fu6$YXKN8VDGEry@;-M#= zw>``;_Tmle({HWw_l+AHQQT`>8g}bs_4xbH?Ky9iE577^oi5587|JcgK3(%+g8b}V z@$`!<1x?t{4(spJ%!HT8Ea#sL0O)bm%1kB-L-1WH;K?#y-UKc2MVukggf zt`)CXk3%yOrni)CXs$Mig!P8=O?6$TmPNl`(6aH;>T$Ujw(z*Ad8yj5J5|$*i$8>< z4=hIiyw#jZd%5;bzpdYP(te>2bocDEj%h!<$rRD>rdhEiSI;jz7q{0u@OoJ*Y=rDX zDEx2YDC_n&{rrHZb;VIdlh9F<9TVgFw)C$3=g#R9nis#a*s83C+3j=Gud*})3umAg z8E=gKcu`P?iQ652A4#Veo({|Hm~GF#6dC?HT;bP0+_rH|OW#~Rxix)onxeaM_$bfX zt{FYxhTygt{{}x1_ii3uRG#s$^b9)&d}#ftoteiX70UV}DZ%CA5$4w?M?W?$U!>2w WFTEHJNcBzgrgI5X-uCe2W&Z<#qcpex literal 0 HcmV?d00001 diff --git a/secrets/keyfile-chocolatebar.bin b/secrets/keyfile-chocolatebar.bin new file mode 100644 index 0000000000000000000000000000000000000000..53bbbf036a0427793c1cd9728fdd5f0b5cb5e052 GIT binary patch literal 4810 zcmXw(_g@W+mqa3&DM@a1_d>Y)-tJ!Ak#%=>@7aTl5{j~^H0{hnJ!L!*Nf~K~ zJQ5xvBH7{V^TYQqIInZg`y8oS8K*SLtsb*oV=~5@tZI-G0*G4_ZnLGtS#8pA9f`mL zV*v)9+^u#Rc}ZLW3=C9|7mim?(kUKWdtg<72{dOVbfz=;i@#6%L14#OmI85q1$ z=uzr{M2-fK;>8#+2pdi;bP!E+G|KD(%QZ-fjbsympiZwv!A`Ou+(avq&*C5{BAkOn z(b!EEGe$=C?$VjZjgb=%7a+4lH=i_Zk zI@qg_YRp_H9wY^#AYyEimkNiu=@@{7MY6jTIG0RC(eZgatinLxS=b&n&0^H3m@>0m zYoUXPR2<92rf>*oEX&Qs;UNZ=i|3Lm&}~a^@L00I* zE+UD+605){B}1E(WNc51VNg{t z9Gy&)6QNKp8V0k2!D5tNq%b4Ra*s$)cCy?lGPX{}CCR*OCD6)*Xhi@jn+tX@r3i?V zAf^+YEE@!a)`>YNok^ynprLd#T&?$-R73>J%asV(ER7SU1af#tfrdokVRd!@OG=lU zO-2G(M-pf$8k|MtR(@8gvp~0upoF0z2pb)&92{^dE#|Y5-R(<3bd42g_(N;I&C? z7f;V(pd>IU9E;?_VHPTguVE$HQ?Mqj$AFP3k$5!^14g=GDlCEuBB=m&8Qx`dm|zx= zTth&5l3ZA)Amxu5lBpC5WEzHuOLgnX613fGf*Y(N7@De8Af*VPP(@IiR00mbVoFN% zYOE@z#zIoSjh;jvpR31m5MU2prvkAk6fBSI=Ftr{JynA-nmtqtL_<-l2`;GCCZwB^ z0B`}(>wyq}G7cYaAv!!fw-ry-D`^O(mSZq^33Q?frc`l_S~Lcw#gMQl2uUq4aok7? zf?=VORRAqT!2qGe8p)r6m}GjA1BgO%w`-CsM1MEI6hS*U}#`?oxq4wbMSmT z0q!O;q?{CwNMR!q*mea#r_s3W0+^R4r&<+CD*{Jkcr|#t8wiInEKYc$1H<;vvOlE^~RbVd?7#iNBnBp4M=08`iiD7;t6GwG~k9^H(mu`E!y zQfXtDnGl$e;pLFrc7t9mH1IWQ1pI#-qZgWZi(})|R;ARY44);WgwOU+qi0*=0RMA} zaEsxDB#=-A6_CAp4qAfoP*_YdPKvZjv}%<}iIN)hTo?{acSs}%zSBlW$w*oeSk2bb z0B|)RE-o%Sg+eqUIYe!eMyYk!wQji>ic(nwCMd)z{F90aNU@2KO0kn;5d%`z_<6#5 zcklg6SVdMg?l{53B7^}fh2h-b05 zTL1a?%Bm(>Y4&59m~@lxiw8hhv^NTI5Vh1(bh^8`YIsNOi`17_PPgZtmMpHDF>0Kt zU}@SdnxOT>1!WY!>sxH}`kk1gX@+i}xx?mN4BpezNu07qd=J@}lnI-Ysw8e$pW{AyT5Ys+rS{5hg+{oNmD_e&oi8SkI?x^!*Z`(-U(6@mEn z2tWDdRzK0oN!P178jmS6S8Ds#D)L5GU5?y3S^5CX92Zd+2VB34J+|Uf%Z2-&doqUd zw{JNcl+Rcjo=sXGRGIO*REi(@F6;IkZj5bZ{WYTxv0+(z^|(=0vLDdO)(%=-Eb&3( zO#RCZv7_#^*Puoy@=Rnf&+lny=$CTyD|kjJJa2aF=%_gvORJ9;=w5$PE|?OIqL2j1 z>4#x#)%m~?Cr54ac?WH2KeH{RUbi@86N&1xY}?lQ6-)2shh4iaJ@;b@yUv~ya6eN|@PGdfo8luaM1Kkt}-BaR|k*O6|R&q|N_Egc)Y>u85! z>g!{9{xR!_Tb~cr=O)I^`T)&Tr#=0*O$53%W)rZTziK%Me|{tF+L+kpLLbbBhAY(M zg};wD*Wti*1j79Q`_e$+?|+ ztgquL3Es}kaV>q<5Lz3WZB5)VI6P95?~gsfU)FuLc=IsKuv2Ac#IAw$9kA7Jx@LR| zxEX(km?wU6=F+&Q%DcZn{`D>KhlP=0o8dLLcI4$RP1vHCMTS3S;`yEnCk7io{Wtl= zu&NpJU*=2x5yoKWXb<2Q00Q6EJo&q3KG3i)?$W7u&?A1Q>M|P-`2S2jG%NHRc&!`1 zp!lz`Wz#DC5BAl%;M;?4?X^C^{>VItlf`e@o$uFHUe^!+S2WJd603EO!9V9Gt{l12 zXDBu;^B-ec6Kz)#(wIIEn7Blo+YmM7*Gk9pXO>O3KfAx5=U3c4n$VUzU=29@bpRCL zJ*i0ooUGoaU){d%){GGsUeD&8nY`p4TK#Q7kv?%xjh`=a{Fy^LeOsQtLpnzGOR<}? zex)5B_#Cbd!)=0}8P*$cyZaaZLP=wu_rR6HE5T2`pBRbyoxFIkkefPV{hEFE@5ior zD4e}*RPpp_hr0=FLnjub1`N=d$Wf{tp^&6;!ygCB;zIuehX!wP---%atE|pDwRxrG z!^Cyil{eY|wV{9AT$~bC5wFx+%+CiyeUIJ=!T9Q52BzNJ-{0DKmO3@ZT{E@~Ie!~? zXAU%K#~}pf)QT=m(78zekW2{l(~K2oMy?p6s=CrWj9Wb7Y^i`UD&*@JoH{V#fc&dj?1 zG{1W4`$s7|?w)UuWZar^XH5JrG802-O5U?LdG~a;yRVNi)K`*o;rH3e1sg_p(4vBf3%`$OMN{79w}LHXA+ zQg3!EMmSqOPTg0Wec@?j?_2c6@m}1CjxayM)!$vE{8GV%u~!Lc2ZP^so{I{@?rBUT&}R1pog4@( z>Wr;Fg`tB^eXR+(j>x?kUwNuJO0%CBP#Yy-R}Rc%G(B5h`IWf}QbhJ&v0&B1qQ{D^ zg!=MK&z;u=Un+?sYYtZQJWJMo4@wwmAHB=AJIk=LC86)s78pLS_Q{tMX~~%lOKZ>0 z`|H>t9GQaGX09wY1*4k-r+3x)S;`~Rn=boCKTKL0w4v0rX^G!J((7=TKKah~H+x>r z@ND2Ecn9`=F|GZ&leXMo3Qs&PvrN5_^f{ok{hI5)kk$54^EUimmpV)~w#yt--9zn? zo4fZ5KNqHM5cK}q*!S*pf|L6q=NV~YZwoV|EP?sT4H)tz?EEn;va=I@W8u>|Gcq@8 zqpqmtzCHFN`^l#oBt#c|EgH`c!()iKdpBhrKhWEI*%(i3#-|6>q(QlXf z!IP=D$Zg3Z*2G_*^N?{NY5oJ(g0SWL5C5WsoIF0JHobuoI;NsMZQQkwvj*iC4lPNS z_ltzc>j977mSMp8vW@J_ZTbVP;YH83t)vwRV}@N`o79mjV;2tk_EEa;E5D5%xq9Z2 zi9s8KY;!r|Kg{K!f?AZ-B zQ2!eGSMBH-`iK2a(?9skFyc$?+U`TQj;0^qy7V3T>7HEt4(ijzE>mWD!B)TAQM17J zYj}dmU!SSB@2Gpy+K%q{9DO!0;lV;`-D4!AbIfyqEB7}q=*E<_%`cw3!el*94a(0! zwv^o)Xo?V{d(K82kd;QH<&2nObjSM}TEDC=qT#a-W(Z7-LL5~@n7 zOe3CmmhN`MSv|_ZPH$iB>4e_f;E1J2UCC_Uuh{+hZMS>D0ryruobto`X_e`0z{lL6 zfbARP2c{NvBd_f>JiL0)l_fgZ|E%}*=0Mi8^8@c?qphXgr!u_naqu4&V*WY&y@I+& z&B?3p{Vsy&y1#82{9dNb8P6KwjvpEwcWL_dqP7e|>i88`N1sX)U~pNi>&@iOtY=1m zp*|$yl>1q6(Tp!$fk!V5J23~wvaPC6)vIz3-qHw83}4@L_vnFI9rkK*&a%~8uD#f^Cul)FZ!*nfMMsUD)GTpq{xh17uwPIb8_3n z40&FiA!2vv#JIpYfxAMdW|#x(in7}vl?`2m)bfCPqAlfj@-owQx4t|VmvHH?tgfYv z-s5X7?AqIR=BxFxsKhU6;eP*wC(~A~xNSJz_-aS$3hkBP;Dsj%2fJ)1FOnz0uT{4` zE$ayU5q)iJ^1q8F*6@5Z-w)1d^qJjA2}zi+oEBiNzcis~cPiL1kFes>+H701Z;x~O z{73%`yd_7h>%#$Vot0emiwSFeI*Q)wj*UG`FDw~O2F3q^loh5$PVEjO#xD(D8n&mq zA`cNWD5|(}`9@zs9_C_Ldu?rw@$?i&r7~t=yyV!{<_25NtO>(E4vue(yua|+kqqYj zNBGsU(JoU?O#bV&(d&kf8VbCh-VNMzBC3dH(N=@lb!i3s=){8CO5^znTb|CA7aUvC zaDx(Ax-<9HiNyPh3O~kPzBr?^rIOm(HmPR$K4@R%i>#s8M}|k25~%;WXkFIQVBgyq zSQ--?uw_%k_ABde&Y0&K5`U=6)=n5TYq3vg%llFn` zm6zmc`T;rhwoMy4dv4|jzqhLI0(VunM69C>Y#UWc{t>Z0KKC93ad&r