Skip to content
Snippets Groups Projects
Commit e2949176 authored by Jens Nolte's avatar Jens Nolte
Browse files

Move /secrets to /etc/secrets

parent 6e3cd3de
No related branches found
No related tags found
No related merge requests found
...@@ -90,11 +90,11 @@ nix copy --file "$nixos_system_file" --argstr hostname "$hostname" --to ssh://ro ...@@ -90,11 +90,11 @@ nix copy --file "$nixos_system_file" --argstr hostname "$hostname" --to ssh://ro
nixos_config_path=$(realpath "$local_temp_dir/nixos-config-$hostname") nixos_config_path=$(realpath "$local_temp_dir/nixos-config-$hostname")
ssh root@$via_host "nixos-install --system $nixos_config_path && sync" ssh root@$via_host "nixos-install --system $nixos_config_path && sync"
ssh root@$via_host mkdir --mode u=rwx,g=,o= --parents /mnt/secrets/passwords ssh root@$via_host mkdir --mode u=rwx,g=,o= --parents /mnt/etc/secrets/passwords
# TODO: get host-specific password # TODO: get host-specific password
#scp -r notThePassword root@$via_host:/mnt/secrets/passwords/root #scp -r notThePassword root@$via_host:/mnt/etc/secrets/passwords/root
#scp -r notThePassword root@$via_host:/mnt/secrets/passwords/jens #scp -r notThePassword root@$via_host:/mnt/etc/secrets/passwords/jens
ssh root@$via_host sync ssh root@$via_host sync
......
...@@ -45,11 +45,11 @@ nix copy --file "$nixos_system_file" --argstr hostname "$hostname" --to ssh://ro ...@@ -45,11 +45,11 @@ nix copy --file "$nixos_system_file" --argstr hostname "$hostname" --to ssh://ro
nixos_config_path=$(realpath "$local_temp_dir/nixos-config-$hostname") nixos_config_path=$(realpath "$local_temp_dir/nixos-config-$hostname")
ssh root@$via_host "nixos-install --system $nixos_config_path && sync" ssh root@$via_host "nixos-install --system $nixos_config_path && sync"
ssh root@$via_host mkdir --mode u=rwx,g=,o= --parents /mnt/secrets/passwords ssh root@$via_host mkdir --mode u=rwx,g=,o= --parents /mnt/etc/secrets/passwords
# TODO: get host-specific password # TODO: get host-specific password
#scp -r notThePassword root@$via_host:/mnt/secrets/passwords/root #scp -r notThePassword root@$via_host:/mnt/etc/secrets/passwords/root
#scp -r notThePassword root@$via_host:/mnt/secrets/passwords/jens #scp -r notThePassword root@$via_host:/mnt/etc/secrets/passwords/jens
ssh root@$via_host sync ssh root@$via_host sync
......
...@@ -77,12 +77,12 @@ ...@@ -77,12 +77,12 @@
mutableUsers = false; mutableUsers = false;
defaultUserShell = pkgs.zsh; defaultUserShell = pkgs.zsh;
users.root = { users.root = {
passwordFile = "/secrets/passwords/root"; passwordFile = "/etc/secrets/passwords/root";
}; };
users.jens = { users.jens = {
uid = 1000; uid = 1000;
isNormalUser = true; isNormalUser = true;
passwordFile = "/secrets/passwords/jens"; passwordFile = "/etc/secrets/passwords/jens";
extraGroups = [ "wheel" "audio" "dialout" ]; extraGroups = [ "wheel" "audio" "dialout" ];
}; };
}; };
......
...@@ -16,7 +16,7 @@ in ...@@ -16,7 +16,7 @@ in
users.users.steam = { users.users.steam = {
isNormalUser = true; isNormalUser = true;
uid = 1100; uid = 1100;
passwordFile = "/secrets/passwords/steam"; passwordFile = "/etc/secrets/passwords/steam";
extraGroups = [ "audio" "input" ]; extraGroups = [ "audio" "input" ];
packages = [ packages = [
customSteam customSteam
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment