Archived
107 lines
4.4 KiB
YAML
107 lines
4.4 KiB
YAML
keys:
|
|
- &admin age1njap586hc0q43kr03g6c8eqhdsmk8zcafkl3f83xwlc2gqhlmfgs4tmwad
|
|
- &docker age19gfn2yedg76dmztm4hncr7vf3r3c9j0qpt4rap7y7gersjk4m3ks2lhd0e
|
|
- &server age1ll6hj5ggruetgjwjfnplpn5xtq35uhlcdflksx3xmnjm6s3uad9sz70jkf
|
|
- &nix-cache age120le4a5l8dh3lyfgvmj3d9ksmej6ajs5mer5y7r0vfg3x9fn69dqf8xgzu
|
|
- &nix-minimal age120whqj96g26lsgy4udvgsn8dc9lumh8jeu3a564fx79rjr5lxffqmrljuu
|
|
- &proxmox-minimal age10at8862478urh0eeuwh8hzln6ck78jgwtztgxatwqlzwagg77y5snm4xzg
|
|
- &lxc-nix-cache age1xjst4frdh0th6q8m7p7u9g5af7ty5jqeum0p6z8a52a9q7st7ewqw8yl9j
|
|
- &lxc-docker age1ezk9x53zt8kcnscdm80jcyf0xq97vndv7jsn3rl8cc0cwm2jmpmq372dzs
|
|
- &lxc-minimal age1jy444f9d9stygj4p3w9kh54cqcfr654tvr75tdvee5cxsgtdtc9q3v60ep
|
|
- &lxc-pxe-boot age1fxxzpnfse8nd9wz78ht3m0plrmraacf4cpga0pe8fm2tdnqcgy8q7qsyvp
|
|
- &lxc-gui age190htw7prp4vln076dxjx3gxxaq06h0zl0te7cqgpx79vl3lhkaes8suy05
|
|
- &proxmox-server age1ukpqxzl44mnjpy5r96sfuc5sqzm47u4k8ujjh5qdgy6jvl9uqgpspymqfk
|
|
- &vm-server age15kh7akxlx7zn00tey79rq2g8lgs4j5y77rcnyfxrxap8ckfu0a9sqvtdhh
|
|
- &baremetal-gui age1ehkswwz2pqaz4svzh7ela5tdnssl8kn6d4vwwxd6zwg8exfpd43syyrrjp
|
|
- &lxc-tor-relay age1vvev5m3shgckl62awa64rtug3lyact7jgxehkuu3vn3wpzulhans75w65s
|
|
- &linode-docker age1eu65wsmez68gegnufl0gqrs0e6w2409mypjlajlq383d7l2e3pjqy5kn6v
|
|
- &linode-gui age17pwyghxr6lq06fw46gwqzhc9ut4paz28rpwx5pmv3cxwak6rgyjsw7lk3w
|
|
- &linode-minimal age1jukmg69cqxnjd0lp5f534jhqe65rxew2hufcmyjxa3rkw6ayef6s2ylcmy
|
|
- &linode-nix-cache age1tzsrtwd3p3lrr9g7nv3z5nvmzsz54t2uc6tfqwutp6usmav83s2sck25cc
|
|
- &linode-server age1rf4kj99wuq59k7w8ar326djmgmpl9hcwlnuag07f8gauq8c3y5mqne87s4
|
|
- &linode-tailscale-exit-node age1d0zhx7u3mfs3nktl67npey87cze4dwsfvfvgaje4rh3gwv500yssckcf6u
|
|
- &lxc-server age1jc6wx33hdhgwhk6nzy5rr8fkgmqxk9um639tk5h632nqfyaw8czskdptj9
|
|
- &lxc-tailscale-exit-node age1pgykvq4pmxhhjrqupcp99fyad2uht40pt79dkzg66cfvsjy5apjqls8u68
|
|
- &proxmox-docker age19ht95nv8uhz2shjmakeut8mc3l5spvrcxs3thhe85an7u02r6sysyv457n
|
|
- &proxmox-gui age1mhaze5tgvc9lwjpml6dnp3xc292337wgm6376yh6tq4fn492ndjq9h23dq
|
|
- &proxmox-nix-cache age15me6sx0f8r58xh9v7aqrj6e99n7eu555jkpw422txpkqt4r02v0qpahlyq
|
|
- &proxmox-pxe-boot age1q3hu6eh3mt4saey7dc3yu04s7knnk2ygpm9xt6mg6rqtem6l0uyq4wzul5
|
|
- &proxmox-tailscale-exit-node age1tczst3x7thwtcz4vce4rg6kmlsszzm6j45kn2nv860z9wa93a92s05ppmc
|
|
|
|
creation_rules:
|
|
# Shared across every currently-deployed host: root/nixos password hash,
|
|
# GitHub access token. Same value on every host today, so every live host's
|
|
# key can decrypt it (matches current risk profile — narrow further in
|
|
# Milestone 4 if hosts should diverge).
|
|
- path_regex: secrets/common\.yaml$
|
|
key_groups:
|
|
- age:
|
|
- *admin
|
|
- *docker
|
|
- *server
|
|
- *nix-cache
|
|
- *lxc-minimal
|
|
- *nix-minimal
|
|
- *lxc-nix-cache
|
|
- *proxmox-minimal
|
|
- *lxc-docker
|
|
- *lxc-pxe-boot
|
|
- *lxc-gui
|
|
- *proxmox-server
|
|
- *vm-server
|
|
- *baremetal-gui
|
|
- *lxc-tor-relay
|
|
- *linode-docker
|
|
- *linode-gui
|
|
- *linode-minimal
|
|
- *linode-nix-cache
|
|
- *linode-server
|
|
- *linode-tailscale-exit-node
|
|
- *lxc-server
|
|
- *lxc-tailscale-exit-node
|
|
- *proxmox-docker
|
|
- *proxmox-gui
|
|
- *proxmox-nix-cache
|
|
- *proxmox-pxe-boot
|
|
- *proxmox-tailscale-exit-node
|
|
|
|
- path_regex: secrets/nix-cache\.yaml$
|
|
key_groups:
|
|
- age:
|
|
- *admin
|
|
- *nix-cache
|
|
- *lxc-nix-cache
|
|
- *linode-nix-cache
|
|
- *proxmox-nix-cache
|
|
|
|
- path_regex: secrets/server\.yaml$
|
|
key_groups:
|
|
- age:
|
|
- *admin
|
|
- *server
|
|
- *proxmox-server
|
|
- *vm-server
|
|
- *linode-server
|
|
- *lxc-server
|
|
|
|
- path_regex: secrets/docker\.yaml$
|
|
key_groups:
|
|
- age:
|
|
- *admin
|
|
- *docker
|
|
|
|
# gui-host-specific secrets (currently: wifi-password, see
|
|
# modules/networking/wifi.nix). Only *lxc-gui has a registered key today
|
|
# -- proxmox-gui/linode-gui/baremetal-gui haven't been provisioned via
|
|
# scripts/secrets/sync-host-keys.sh yet, so whichever variant is actually
|
|
# deployed next needs its recipient added here (and `sops updatekeys` rerun)
|
|
# before it can decrypt this.
|
|
- path_regex: secrets/gui\.yaml$
|
|
key_groups:
|
|
- age:
|
|
- *admin
|
|
- *lxc-gui
|
|
- *baremetal-gui
|
|
- *linode-gui
|
|
- *proxmox-gui
|