feat: use private sops repo for secrets

This commit is contained in:
matt1432 2023-12-05 20:15:27 -05:00
parent 956e845635
commit 117162cd5d
3 changed files with 4 additions and 4 deletions

View file

@ -5,14 +5,14 @@
...
}: let
caddy = caddy-plugins.packages.${pkgs.system}.default;
# TODO: use agenix?
verySecretToken = "TODO";
in {
imports = [caddy-plugins.nixosModules.default];
environment.systemPackages = [caddy];
users.users.${config.vars.user}.extraGroups = ["caddy"];
systemd.services.caddy.serviceConfig.EnvironmentFile =
config.sops.secrets.caddy-cloudflare.path;
services.caddy = {
enable = true;
enableReload = false;
@ -28,7 +28,7 @@ in {
serverAliases = ["*.nelim.org"];
extraConfig = ''
tls {
dns cloudflare ${verySecretToken}
dns cloudflare {$TLS}
resolvers 1.0.0.1
}
'';

Binary file not shown.

BIN
flake.nix

Binary file not shown.