Parametrize networking, users, and containers modules under myNetworking/myUsers/myContainers so both hosts share the same logic instead of duplicating it, and split desktop/server module imports into modules/profiles/. Adds hosts/vps (not installed yet, hardware config and bootloader device are placeholders) to run Traefik, Headscale, Headplane, and Gitea via a combined Docker Compose stack. Wires up agenix for secrets and migrates miku-homelab's WireGuard private key off a plain filesystem path into an encrypted secrets/miku-homelab-wg.age. The vps side of that tunnel still needs its own key generated and encrypted after install. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
21 lines
1.0 KiB
Nix
21 lines
1.0 KiB
Nix
let
|
|
# Emma's personal SSH keys (same ones authorized in modules/system/users.nix),
|
|
# so secrets can be edited/re-keyed from her own workstations.
|
|
emma-main-pc = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIA8vfwM5g9RJXqHtqTgNqsYg9SxSm+UMvFqTjBoAsLJ6 emmatherock@MAIN-PC";
|
|
emma-s21-plus = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIpTslcK0yQ6k+h8foNl17wVRyJUfEGzq7f1h3014WNB s21 plus";
|
|
|
|
# Host SSH host keys, used by agenix at runtime to decrypt (via the default
|
|
# age.identityPaths, which points at services.openssh host keys).
|
|
miku-homelab = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIH7zsQdzX7RHRd2plwrTKJR89uwR2YfzBm1n+HkcYEbb root@NixOS";
|
|
|
|
# TODO: replace with the real vps SSH host key once the host is installed
|
|
# (e.g. via `ssh-keyscan` or by reading /etc/ssh/ssh_host_ed25519_key.pub on
|
|
# the vps itself), then re-key any vps secrets that were encrypted without it.
|
|
vps = "ssh-ed25519 REPLACE_ME_AFTER_VPS_INSTALL";
|
|
|
|
admins = [ emma-main-pc emma-s21-plus ];
|
|
in
|
|
{
|
|
"miku-homelab-wg.age".publicKeys = admins ++ [ miku-homelab ];
|
|
}
|