Archived
110 lines
4.4 KiB
YAML
110 lines
4.4 KiB
YAML
keys:
|
|
- &admin age1njap586hc0q43kr03g6c8eqhdsmk8zcafkl3f83xwlc2gqhlmfgs4tmwad
|
|
- &docker age19gfn2yedg76dmztm4hncr7vf3r3c9j0qpt4rap7y7gersjk4m3ks2lhd0e
|
|
- &server age1ll6hj5ggruetgjwjfnplpn5xtq35uhlcdflksx3xmnjm6s3uad9sz70jkf
|
|
- &nix-cache age120le4a5l8dh3lyfgvmj3d9ksmej6ajs5mer5y7r0vfg3x9fn69dqf8xgzu
|
|
- &nix-minimal age120whqj96g26lsgy4udvgsn8dc9lumh8jeu3a564fx79rjr5lxffqmrljuu
|
|
- &proxmox-minimal age10at8862478urh0eeuwh8hzln6ck78jgwtztgxatwqlzwagg77y5snm4xzg
|
|
- &lxc-gui age190htw7prp4vln076dxjx3gxxaq06h0zl0te7cqgpx79vl3lhkaes8suy05
|
|
- &baremetal-gui age1adur9g330gua4l6ndk8cqjg35qc8yxwgme6wrl2hpylcc7vxm38q05ejuy
|
|
- &linode-docker age17e89ty6p0fw24daanen57wg8uald9s025t3wwxsw269svwpmgvrshfvfvt
|
|
- &linode-gui age1hrx8qj02fj2ea6d4g9vqhyj9hl7fppkjqfdx2l37py3h6pdkr95s8n8rvs
|
|
- &linode-minimal age1e7l8dusgmgfzd2cxrrzwepzjxt69hzqj4epee0cs27u6yg4kxcuqm34ncx
|
|
- &linode-nix-cache age1jcx3yajjhghn8qh8za3yeu8nxykzlg3p4nrv03vnfvzl0mzayg2qmg940e
|
|
- &linode-server age1sweerhrga9yf8x6sv0apz4ed4g48rnlcq34rpv20t0rcelwgpgeqwvndzz
|
|
- &linode-tailscale-subnet-router age1f7usptjx9rv4rxauasve200gxtdt9jkqhhdqstlf20wvlm7u75rsjfw50m
|
|
- &lxc-docker age17jqc66x9yeshfgd9v78mj483r4zzarqdtuxtrkxe4x5mw679gphshd94th
|
|
- &lxc-minimal age1px0h5l9zp2dww0m8fncrc82kfdmzplsfv2ltat7sna28xpg09pqqcl3s2k
|
|
- &lxc-nix-cache age1ufg390ydrmma849t9xfkxxl5xvdkk6mngnlzhmy7mvuaje8sgcmsmnq6l7
|
|
- &lxc-pxe-boot age16j42pdc5dr6wnj7xayhkqdj2rny9u68fcqejs50hqq42scssh4gsnrrnlt
|
|
- &lxc-server age1nruncs4l0ufk7yuc4des8p99c0alfndl0lhsws8tycl5pplfp56s30af5f
|
|
- &lxc-tailscale-subnet-router age1k7d2du5mejsmv5rzavm4xwgpthqvcfsehduquv28nzs53zppa3kqngfxq2
|
|
- &lxc-tor-relay age16kqfmvz4e23hmdlqresnyw69ej604s320mmd49h4hm3fhqchtgyqrws0k2
|
|
- &proxmox-docker age1arhf2q45zw6wf2uevju4savp575x3m2tfvved5zzq3ay92ynua9s3cm92c
|
|
- &proxmox-gui age19mn8zrxl8zpps9yvrh4euquvygpp4fp8queg7xc6qhtnl4ng8c9qx02qwn
|
|
- &proxmox-nix-cache age1jlltcv5jcnm40z5k0q6hv053k2rqpqvemtuecdwn527uw8uqz4es3x7m68
|
|
- &proxmox-pxe-boot age1ug787sgt6st6k82fgkrug2lzltw4qsukrrqqs3w27ewwqj8rg4hsxcmylz
|
|
- &proxmox-server age1529taqdwr6t0w7cvzmty0d5y5593wffl0krt48j6uc4u39k56g2qf6ywtp
|
|
- &proxmox-tailscale-subnet-router age1zhfyuzlq40reuqlr34gf77852nhs3t6mqfzrqmas8z6sxk7tcfhsungrm0
|
|
|
|
creation_rules:
|
|
# Shared across every currently-deployed host: root/nixos password hash,
|
|
# GitHub access token. Same value on every host today, so every live host's
|
|
# key can decrypt it (matches current risk profile — narrow further in
|
|
# Milestone 4 if hosts should diverge).
|
|
- path_regex: secrets/common\.yaml$
|
|
key_groups:
|
|
- age:
|
|
- *admin
|
|
- *docker
|
|
- *server
|
|
- *nix-cache
|
|
- *nix-minimal
|
|
- *proxmox-minimal
|
|
- *lxc-gui
|
|
- *baremetal-gui
|
|
- *linode-docker
|
|
- *linode-gui
|
|
- *linode-minimal
|
|
- *linode-nix-cache
|
|
- *linode-server
|
|
- *linode-tailscale-subnet-router
|
|
- *lxc-docker
|
|
- *lxc-minimal
|
|
- *lxc-nix-cache
|
|
- *lxc-pxe-boot
|
|
- *lxc-server
|
|
- *lxc-tailscale-subnet-router
|
|
- *lxc-tor-relay
|
|
- *proxmox-docker
|
|
- *proxmox-gui
|
|
- *proxmox-nix-cache
|
|
- *proxmox-pxe-boot
|
|
- *proxmox-server
|
|
- *proxmox-tailscale-subnet-router
|
|
|
|
- path_regex: secrets/nix-cache\.yaml$
|
|
key_groups:
|
|
- age:
|
|
- *admin
|
|
- *nix-cache
|
|
- *linode-nix-cache
|
|
- *lxc-nix-cache
|
|
- *proxmox-nix-cache
|
|
|
|
- path_regex: secrets/server\.yaml$
|
|
key_groups:
|
|
- age:
|
|
- *admin
|
|
- *server
|
|
- *linode-server
|
|
- *lxc-server
|
|
- *proxmox-server
|
|
|
|
- path_regex: secrets/docker\.yaml$
|
|
key_groups:
|
|
- age:
|
|
- *admin
|
|
- *docker
|
|
|
|
- path_regex: secrets/tor-relay\.yaml$
|
|
key_groups:
|
|
- age:
|
|
- *admin
|
|
- *lxc-tor-relay
|
|
|
|
# gui-host-specific secrets (currently: wifi-password, see
|
|
# modules/networking/wifi.nix). Only *lxc-gui has a registered key today
|
|
# -- proxmox-gui/linode-gui/baremetal-gui haven't been provisioned via
|
|
# scripts/secrets/sync-host-keys.sh yet, so whichever variant is actually
|
|
# deployed next needs its recipient added here (and `sops updatekeys` rerun)
|
|
# before it can decrypt this.
|
|
- path_regex: secrets/gui\.yaml$
|
|
key_groups:
|
|
- age:
|
|
- *admin
|
|
- *lxc-gui
|
|
- *baremetal-gui
|
|
- *linode-gui
|
|
- *proxmox-gui
|