jungle/secrets/secrets.nix

18 lines
534 B
Nix
Raw Permalink Normal View History

let
keys = import ../keys.nix;
adminsKeys = builtins.attrValues keys.admins;
hut = [ keys.hosts.hut ] ++ adminsKeys;
# Only expose ceph keys to safe nodes and admins
2023-09-08 19:01:57 +02:00
safe = keys.hostGroup.safe ++ adminsKeys;
in
{
"gitea-runner-token.age".publicKeys = hut;
"gitlab-runner-docker-token.age".publicKeys = hut;
"gitlab-runner-shell-token.age".publicKeys = hut;
2023-09-12 12:19:43 +02:00
"nix-serve.age".publicKeys = hut;
"jungle-robot-password.age".publicKeys = hut;
2023-09-08 19:01:57 +02:00
"ceph-user.age".publicKeys = safe;
"munge-key.age".publicKeys = safe;
}