Use GRUB BIOS boot + move sops age key out of repo
This commit is contained in:
parent
1862821f8f
commit
b419320bfc
2 changed files with 10 additions and 2 deletions
|
|
@ -5,6 +5,11 @@
|
||||||
i18n.defaultLocale = "en_US.UTF-8";
|
i18n.defaultLocale = "en_US.UTF-8";
|
||||||
system.stateVersion = "25.11";
|
system.stateVersion = "25.11";
|
||||||
|
|
||||||
|
boot.loader.systemd-boot.enable = false;
|
||||||
|
boot.loader.grub.enable = true;
|
||||||
|
boot.loader.grub.device = "/dev/vda";
|
||||||
|
boot.loader.efi.canTouchEfiVariables = false;
|
||||||
|
|
||||||
virtualisation.vmVariant = {
|
virtualisation.vmVariant = {
|
||||||
users.mutableUsers = false;
|
users.mutableUsers = false;
|
||||||
users.users.tobias.password = "admin";
|
users.users.tobias.password = "admin";
|
||||||
|
|
|
||||||
|
|
@ -1,8 +1,11 @@
|
||||||
{ config, ... }:
|
{ config, ... }:
|
||||||
{
|
{
|
||||||
environment.etc."sops/age/keys.txt".source = ../../secrets/age/keys.txt;
|
|
||||||
sops.defaultSopsFile = ../../secrets/bucur.yaml;
|
sops.defaultSopsFile = ../../secrets/bucur.yaml;
|
||||||
sops.age.keyFile = "/etc/sops/age/keys.txt";
|
sops.age.keyFile = "/var/lib/sops/age/keys.txt";
|
||||||
|
|
||||||
|
systemd.tmpfiles.rules = [
|
||||||
|
"d /var/lib/sops/age 0700 root root -"
|
||||||
|
];
|
||||||
|
|
||||||
sops.secrets.mtproto_secret = {};
|
sops.secrets.mtproto_secret = {};
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue