From 519963707ae3c6f8057c78cd7aa1e62cfd3db1d0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Benjamin=20B=C3=A4dorf?= Date: Thu, 20 Jul 2023 23:36:40 +0200 Subject: [PATCH] feat: deploy droppie root user ssh private key via nix --- hosts/droppie/droppie.nix | 7 +++++++ secrets/droppie-ssh-root.key | Bin 0 -> 1755 bytes secrets/secrets.nix | 2 ++ 3 files changed, 9 insertions(+) create mode 100644 secrets/droppie-ssh-root.key diff --git a/hosts/droppie/droppie.nix b/hosts/droppie/droppie.nix index 8c561040..1dc9804c 100644 --- a/hosts/droppie/droppie.nix +++ b/hosts/droppie/droppie.nix @@ -48,5 +48,12 @@ in { mode = "400"; owner = "root"; }; + + age.secrets."droppie-ssh-root.key" = { + file = "${self}/secrets/droppie-ssh-root.key"; + path = "/home/${psCfg.user.name}/.ssh/id_ed25519"; + mode = "400"; + owner = psCfg.user.name; + }; }; } diff --git a/secrets/droppie-ssh-root.key b/secrets/droppie-ssh-root.key new file mode 100644 index 0000000000000000000000000000000000000000..fa6fde640b043bafbd4d91ae278c80a0f26959be GIT binary patch literal 1755 zcmYk4Ym6KP0e}@7(V>W!+M~o+k26gQ%Q-Xq-U@}?o%hbn&d$uv?936!?#|BcJa-;D zyECJqB;_H!rVZDU2BY;64XH#hQ9()xQ42|%*3?+<4lEBf3fTCg7S4cR)E_4P|B^5H z@^y!UrGeWI5^rLR-7k-WAvlGBrM(MbI9eKL*+K!XERj>?568$DI)- z=O;8-ZsJ+mi;;{Sc3~jyxe?m#4e^HIXZk$Gh+(ao(~G5%T%ZZKFeTlL0{S&ImauqO z5yeV_&2%W5p0d4|bSgkdy3=f33X%em5XE*d#=40crZr}kSQWBLr-c#5C}A?9hhiy@ z=QLKSUr(lUq{V`B3Ra8Qx6eHCdBbDy)s>qI`@t_yACw0_l5fM@?4oem-aC&Fb zuOXt1+Mpi0E(Jk$76q`PItbmd?s-ha;51Zihj_O2|Fta)5uhqSMcml4^ztmIApM|M zj1n7?H76!nMKa(N^m7%N5cZZTfS9=jY0#}8CC2{zS-dw zcMR1SkFxVgP3W*i&~6}8wk+1NxDFA9RZl^ZkER;aXyAa$%%G_*BRtxU5t!FptskN+ z#^u}95;tuYY%<%1bi?B(QX;{i`XA1aQ6i(nJYCI9MWDu6eNvVqwQNtEN><61xt`Tw zmZMvx38F(_s&$4aUx^A!5Xo<8!U7%XX^y$O@+*f&Q`IQR~{(AfL@>}{Mw|;ZuXIFlC z;TM}Pa_aLprKc9xKle!Y{OOD9#~0}*-hSv#__;F=oR@d(9{uXvqrTCHGcxUgAbGaQ?A14=A z#OpTS*!#or_1$fx_1lx5sy!8aci*|kpM2)E8}9iHbs*X}Z4S2`UEKNXJ$LUBPJVP| zTYhox@>lksoj+Fl*z)yP#LMC2OK;xw$_M_Hqt<@)v+<#x&u>4=9XNCD)$iSU>BLj_ L3i}@ literal 0 HcmV?d00001 diff --git a/secrets/secrets.nix b/secrets/secrets.nix index eef6775c..b04b58ce 100644 --- a/secrets/secrets.nix +++ b/secrets/secrets.nix @@ -49,6 +49,8 @@ in { "dyndns-droppie.key".publicKeys = droppieKeys ++ baseKeys; + "droppie-ssh-root.key".publicKeys = droppieKeys ++ baseKeys; + "mopidy.conf".publicKeys = chocolatebarKeys ++ biolimoKeys ++ baseKeys; "b12f-env-secrets".publicKeys = biolimoKeys ++ chocolatebarKeys ++ baseKeys;