tor-relay: wire beszel-agent with token secret and fix sops key #51

Merged
beatzaplenty merged 1 commits from worktree-tor-relay-beszel into main 2026-07-23 23:53:01 +00:00
Owner
  • Add hosts/tor-relay/host.nix import of host-token.nix so the agent
    gets its TOKEN from a sops-managed environment file
  • Add secrets/tor-relay.yaml (encrypted beszel token for this host)
  • Add creation_rules entry for secrets/tor-relay.yaml in .sops.yaml
  • Update &lxc-tor-relay age key to the host's actual current key
    (old key was from a prior LXC incarnation; new key extracted from
    Switch-nix output: age1gl5ujmhd2pe37...)
  • Re-encrypt secrets/common.yaml via sops updatekeys to swap in the
    new key, so the host can decrypt its password hash on next boot

Co-Authored-By: Claude Sonnet 4.6 noreply@anthropic.com

- Add hosts/tor-relay/host.nix import of host-token.nix so the agent gets its TOKEN from a sops-managed environment file - Add secrets/tor-relay.yaml (encrypted beszel token for this host) - Add creation_rules entry for secrets/tor-relay.yaml in .sops.yaml - Update &lxc-tor-relay age key to the host's actual current key (old key was from a prior LXC incarnation; new key extracted from Switch-nix output: age1gl5ujmhd2pe37...) - Re-encrypt secrets/common.yaml via sops updatekeys to swap in the new key, so the host can decrypt its password hash on next boot Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
beatzaplenty added 1 commit 2026-07-23 23:52:58 +00:00
tor-relay: wire beszel-agent with token secret and fix sops key
Check NixOS configurations / eval-hosts (pull_request) Successful in 11m2s
e368f68ad7
- Add hosts/tor-relay/host.nix import of host-token.nix so the agent
  gets its TOKEN from a sops-managed environment file
- Add secrets/tor-relay.yaml (encrypted beszel token for this host)
- Add creation_rules entry for secrets/tor-relay.yaml in .sops.yaml
- Update &lxc-tor-relay age key to the host's actual current key
  (old key was from a prior LXC incarnation; new key extracted from
  Switch-nix output: age1gl5ujmhd2pe37...)
- Re-encrypt secrets/common.yaml via sops updatekeys to swap in the
  new key, so the host can decrypt its password hash on next boot

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
beatzaplenty merged commit 0bf99c56cc into main 2026-07-23 23:53:01 +00:00
This repo is archived. You cannot comment on pull requests.
No Reviewers
No labels
1 Participants
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: beatzaplenty/nixos#51