jungle/secrets/secrets.nix

18 lines
501 B
Nix
Raw Normal View History

let
keys = import ../keys.nix;
adminsKeys = builtins.attrValues keys.admins;
hut = [ keys.hosts.hut ] ++ adminsKeys;
# Only expose ceph keys to safe nodes and admins
2023-09-08 19:01:57 +02:00
safe = keys.hostGroup.safe ++ adminsKeys;
in
{
2023-09-28 14:11:30 +02:00
"gitlab-bsc-es-token.age".publicKeys = hut;
"gitea-runner-token.age".publicKeys = hut;
"ovni-token.age".publicKeys = hut;
"nosv-token.age".publicKeys = hut;
2023-09-12 12:19:43 +02:00
"nix-serve.age".publicKeys = hut;
2023-09-08 19:01:57 +02:00
"ceph-user.age".publicKeys = safe;
"munge-key.age".publicKeys = safe;
}