feat(secrets): wire up real vps SSH host key and new admin key
Fills in the real vps host key (replacing the install placeholder) and registers vps-wg.age for agenix. Also adds Emma's NixOS-machine SSH key as an admin decrypt key and to the vps host's authorizedKeys. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
1 parent
d0cb1b5090
commit
f3ddbb162c
2 files changed
+6
-6
No files matched your search
@@ -46,6 +46,7 @@
|
|||||||
authorizedKeys = [
|
authorizedKeys = [
|
||||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIA8vfwM5g9RJXqHtqTgNqsYg9SxSm+UMvFqTjBoAsLJ6 emmatherock@MAIN-PC"
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIA8vfwM5g9RJXqHtqTgNqsYg9SxSm+UMvFqTjBoAsLJ6 emmatherock@MAIN-PC"
|
||||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIpTslcK0yQ6k+h8foNl17wVRyJUfEGzq7f1h3014WNB s21 plus"
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIpTslcK0yQ6k+h8foNl17wVRyJUfEGzq7f1h3014WNB s21 plus"
|
||||||
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEUCpjAuJobymPPAoPjLdL1eD6g4v6wrquu3cyHP22Wj emmatherock@NixOS"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
+5
-6
@@ -1,20 +1,19 @@
|
|||||||
let
|
let
|
||||||
# Emma's personal SSH keys (same ones authorized in modules/system/users.nix),
|
# Emma's personal SSH keys (same ones authorized in modules/system/users.nix),
|
||||||
# so secrets can be edited/re-keyed from her own workstations.
|
# so secrets can be edited/re-keyed from his own workstations.
|
||||||
emma-main-pc = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIA8vfwM5g9RJXqHtqTgNqsYg9SxSm+UMvFqTjBoAsLJ6 emmatherock@MAIN-PC";
|
emma-main-pc = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIA8vfwM5g9RJXqHtqTgNqsYg9SxSm+UMvFqTjBoAsLJ6 emmatherock@MAIN-PC";
|
||||||
emma-s21-plus = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIpTslcK0yQ6k+h8foNl17wVRyJUfEGzq7f1h3014WNB s21 plus";
|
emma-s21-plus = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIpTslcK0yQ6k+h8foNl17wVRyJUfEGzq7f1h3014WNB s21 plus";
|
||||||
|
emma-nixos = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEUCpjAuJobymPPAoPjLdL1eD6g4v6wrquu3cyHP22Wj emmatherock@NixOS";
|
||||||
|
|
||||||
# Host SSH host keys, used by agenix at runtime to decrypt (via the default
|
# Host SSH host keys, used by agenix at runtime to decrypt (via the default
|
||||||
# age.identityPaths, which points at services.openssh host keys).
|
# age.identityPaths, which points at services.openssh host keys).
|
||||||
miku-homelab = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIH7zsQdzX7RHRd2plwrTKJR89uwR2YfzBm1n+HkcYEbb root@NixOS";
|
miku-homelab = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIH7zsQdzX7RHRd2plwrTKJR89uwR2YfzBm1n+HkcYEbb root@NixOS";
|
||||||
|
|
||||||
# TODO: replace with the real vps SSH host key once the host is installed
|
vps = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDh8+hpWkGLRszFI4TC1/YHB8IiSdM0UUOsWbOwXPLn6 root@vps";
|
||||||
# (e.g. via `ssh-keyscan` or by reading /etc/ssh/ssh_host_ed25519_key.pub on
|
|
||||||
# the vps itself), then re-key any vps secrets that were encrypted without it.
|
|
||||||
vps = "ssh-ed25519 REPLACE_ME_AFTER_VPS_INSTALL";
|
|
||||||
|
|
||||||
admins = [ emma-main-pc emma-s21-plus ];
|
admins = [ emma-main-pc emma-s21-plus emma-nixos ];
|
||||||
in
|
in
|
||||||
{
|
{
|
||||||
"miku-homelab-wg.age".publicKeys = admins ++ [ miku-homelab ];
|
"miku-homelab-wg.age".publicKeys = admins ++ [ miku-homelab ];
|
||||||
|
"vps-wg.age".publicKeys = admins ++ [ vps ];
|
||||||
}
|
}
|
||||||
Reference in new issue
Block a user