From 2114c6c347d4b45e7419c2827311baf68230767e Mon Sep 17 00:00:00 2001 From: andromeda Date: Mon, 5 Jan 2026 14:35:42 +0100 Subject: rename secrets --- machines/109-199-104-83/configuration.nix | 2 +- machines/lenovo/configuration.nix | 4 ---- pub-keys.nix | 7 +++---- secrets/andromeda-pw.age | 7 +++++++ secrets/mailserver-acc-test-pw.age | 9 +++++++++ secrets/mtgmonkey-pw.age | Bin 0 -> 396 bytes secrets/secret0.age | 7 ------- secrets/secret1.age | Bin 396 -> 0 bytes secrets/secret2.age | Bin 506 -> 0 bytes secrets/secret3.age | 9 --------- secrets/secrets.nix | 7 +++---- users.nix | 4 ++-- 12 files changed, 25 insertions(+), 31 deletions(-) create mode 100644 secrets/andromeda-pw.age create mode 100644 secrets/mailserver-acc-test-pw.age create mode 100644 secrets/mtgmonkey-pw.age delete mode 100644 secrets/secret0.age delete mode 100644 secrets/secret1.age delete mode 100644 secrets/secret2.age delete mode 100644 secrets/secret3.age diff --git a/machines/109-199-104-83/configuration.nix b/machines/109-199-104-83/configuration.nix index 2699370..c9785cd 100644 --- a/machines/109-199-104-83/configuration.nix +++ b/machines/109-199-104-83/configuration.nix @@ -25,7 +25,7 @@ x509.useACMEHost = config.mailserver.fqdn; loginAccounts = { "test@${config.networking.domain}" = { - hashedPasswordFile = builtins.toString config.age.secrets.secret3.path; + hashedPasswordFile = builtins.toString config.age.secrets.mailserver-acc-test-pw.path; }; }; }; diff --git a/machines/lenovo/configuration.nix b/machines/lenovo/configuration.nix index adf0814..152d136 100644 --- a/machines/lenovo/configuration.nix +++ b/machines/lenovo/configuration.nix @@ -9,10 +9,6 @@ ./impermanence.nix (modulesPath + "/installer/scan/not-detected.nix") ]; - age.secrets = { - secret0.file = ../../secrets/secret0.age; - secret1.file = ../../secrets/secret1.age; - }; boot.loader = { efi.canTouchEfiVariables = true; systemd-boot.enable = true; diff --git a/pub-keys.nix b/pub-keys.nix index 8bf4995..fcaa7d8 100644 --- a/pub-keys.nix +++ b/pub-keys.nix @@ -1,9 +1,8 @@ { age.secrets = { - secret0.file = ./secrets/secret0.age; - secret1.file = ./secrets/secret1.age; - secret2.file = ./secrets/secret2.age; - secret3.file = ./secrets/secret3.age; + andromeda-pw.file = ./secrets/andromeda-pw.age; + mtgmonkey-pw.file = ./secrets/mtgmonkey-pw.age; + mailserver-acc-test-pw.file = ./secrets/mailserver-acc-test-pw.age; }; pub-keys = { ssh = { diff --git a/secrets/andromeda-pw.age b/secrets/andromeda-pw.age new file mode 100644 index 0000000..757e7ff --- /dev/null +++ b/secrets/andromeda-pw.age @@ -0,0 +1,7 @@ +age-encryption.org/v1 +-> ssh-ed25519 mT2fyg 4fCTrNibFdjnVfsIbXi6plbd56K8ZDDqtgryXPk2SUA +vKlbDi+HpyYlSsN39GRh6GRwdHRSjypCEqguOaHPFDM +-> ssh-ed25519 UHxfvA RqrDa4xJoAy1Gdzvq6Z5eTSNTDtHzUmzRoLC+j+HxiI ++5CohUFSDB9oiLU0T25FKrQrz07DCviVuzZsVcUltOc +--- SQ5zQx9lL5UdNinOgP6yG5WWiBdhSwFqJVt6u3SNpLA +6 UpQ]N;K;1y J -'(2ܝf=NtfCuFN9k9dY"FQ<sѬo \ No newline at end of file diff --git a/secrets/mailserver-acc-test-pw.age b/secrets/mailserver-acc-test-pw.age new file mode 100644 index 0000000..c38cb97 --- /dev/null +++ b/secrets/mailserver-acc-test-pw.age @@ -0,0 +1,9 @@ +age-encryption.org/v1 +-> ssh-ed25519 mT2fyg slLOkD/9TAYOuZ/g5U4NvPWUlmYZeie12xzggioviw0 +E0uAj4RMgv7DTJpvtEO54G9XHNLFOgFflR54Cl6/X8g +-> ssh-ed25519 UHxfvA xHFujOdegur0PLNHZP+h5RxHhVD2K906NZx7nprMkUs +PdDxzD5QBdE/yWPMnF+CDGROEpE4nYvg12v1G3QK9XI +-> ssh-ed25519 Xoin5w YWsO9HtEFB79+aKr6eWi5Sg5geKfzT+IrDy2L5qEmx4 +sXLRmcRDyAv64nSGs8QXcHmKYO+F11Pzea1EVGmpEys +--- Sjg8SqkkEEL4X0G1GOUoHO702ZtrM0hMniIdS7yIsDA +'B(7Dϓ=hh fɮxT!K.~س,ߓD|+p"tGyQRcPQQ Ս=qiא ssh-ed25519 mT2fyg 4fCTrNibFdjnVfsIbXi6plbd56K8ZDDqtgryXPk2SUA -vKlbDi+HpyYlSsN39GRh6GRwdHRSjypCEqguOaHPFDM --> ssh-ed25519 UHxfvA RqrDa4xJoAy1Gdzvq6Z5eTSNTDtHzUmzRoLC+j+HxiI -+5CohUFSDB9oiLU0T25FKrQrz07DCviVuzZsVcUltOc ---- SQ5zQx9lL5UdNinOgP6yG5WWiBdhSwFqJVt6u3SNpLA -6 UpQ]N;K;1y J -'(2ܝf=NtfCuFN9k9dY"FQ<sѬo \ No newline at end of file diff --git a/secrets/secret1.age b/secrets/secret1.age deleted file mode 100644 index facb97b..0000000 Binary files a/secrets/secret1.age and /dev/null differ diff --git a/secrets/secret2.age b/secrets/secret2.age deleted file mode 100644 index 993e770..0000000 Binary files a/secrets/secret2.age and /dev/null differ diff --git a/secrets/secret3.age b/secrets/secret3.age deleted file mode 100644 index c38cb97..0000000 --- a/secrets/secret3.age +++ /dev/null @@ -1,9 +0,0 @@ -age-encryption.org/v1 --> ssh-ed25519 mT2fyg slLOkD/9TAYOuZ/g5U4NvPWUlmYZeie12xzggioviw0 -E0uAj4RMgv7DTJpvtEO54G9XHNLFOgFflR54Cl6/X8g --> ssh-ed25519 UHxfvA xHFujOdegur0PLNHZP+h5RxHhVD2K906NZx7nprMkUs -PdDxzD5QBdE/yWPMnF+CDGROEpE4nYvg12v1G3QK9XI --> ssh-ed25519 Xoin5w YWsO9HtEFB79+aKr6eWi5Sg5geKfzT+IrDy2L5qEmx4 -sXLRmcRDyAv64nSGs8QXcHmKYO+F11Pzea1EVGmpEys ---- Sjg8SqkkEEL4X0G1GOUoHO702ZtrM0hMniIdS7yIsDA -'B(7Dϓ=hh fɮxT!K.~س,ߓD|+p"tGyQRcPQQ Ս=qiא