sops on hosts file

This commit is contained in:
2026-10-06 06:40:37 +05:00
parent f7720a7415
commit 163c7e5f72
8 changed files with 160 additions and 5 deletions
+3
View File
@@ -1,3 +1,6 @@
# nixos-rebuild build / nix build output symlinks
result
result-*
# local-only /etc/hosts entries, kept out of this public repo
hosts/la2410/private-hosts
+7
View File
@@ -0,0 +1,7 @@
keys:
- &la2410 age1q7nppjnvr4ejgeqrlx08z7leyzarvn83fdp87p4wwy0sgdmspddqufv0ak
creation_rules:
- path_regex: hosts/la2410/secrets\.yaml$
key_groups:
- age:
- *la2410
+91 -1
View File
@@ -1,3 +1,93 @@
# dotfiles
~/.config and some config for my linux box
~/.config and some config for my linux box
NixOS + home-manager flake for `la2410`. All commands below run from the repo root:
```bash
cd ~/git/sargit/dotfiles
```
## Apply changes
```bash
doas nixos-rebuild switch --flake .#la2410
```
New files must be `git add`ed first, or the flake can't see them.
Other modes:
```bash
doas nixos-rebuild test --flake .#la2410 # activate now, but don't add a boot entry
doas nixos-rebuild boot --flake .#la2410 # only use it from the next boot
nixos-rebuild build --flake .#la2410 # just build it, leaves ./result
```
## Update
```bash
nix flake update # bump all inputs (nixpkgs, home-manager, sops-nix)
nix flake update nixpkgs # bump just one
doas nixos-rebuild switch --flake .#la2410
git commit flake.lock -m "update"
```
Run `nix flake update` as yourself, not with doas, so `flake.lock` stays owned by you.
To move to a new NixOS release (e.g. 26.11), change the `nixos-26.05` and `release-26.05` branches in `flake.nix`, then update as above. Leave `system.stateVersion` alone.
## Roll back
```bash
doas nixos-rebuild switch --rollback
nixos-rebuild list-generations
```
Or pick an older generation in the GRUB menu at boot.
## Clean up
```bash
doas nix-collect-garbage --delete-older-than 14d
nix-collect-garbage --delete-older-than 14d # your user profile
nix store optimise
```
## Find and try packages
```bash
nix search nixpkgs <name>
nix shell nixpkgs#<pkg> # temporary shell with it
nix run nixpkgs#<pkg> # run it once
```
To install a package permanently, add it to `environment.systemPackages` in `hosts/la2410/configuration.nix` and rebuild.
## Private /etc/hosts entries (sops)
Private hosts are stored encrypted in `hosts/la2410/secrets.yaml`, decrypted with the machine's SSH host key. Public ones go straight into `networking.extraHosts`.
Edit them:
```bash
doas env SOPS_AGE_KEY_CMD="nix run nixpkgs#ssh-to-age -- -private-key -i /etc/ssh/ssh_host_ed25519_key" \
nix run nixpkgs#sops -- hosts/la2410/secrets.yaml
```
Add lines under `private-hosts: |`, save, then rebuild.
If the SSH host key ever changes (reinstall), get the new age key, put it in `.sops.yaml`, and re-encrypt with the old key still available:
```bash
nix run nixpkgs#ssh-to-age -- -i /etc/ssh/ssh_host_ed25519_key.pub
doas env SOPS_AGE_KEY_CMD="..." nix run nixpkgs#sops -- updatekeys hosts/la2410/secrets.yaml
```
## Debugging a failed build
```bash
doas nixos-rebuild switch --flake .#la2410 --show-trace
journalctl -b -p err # errors this boot
systemctl --failed
```
Generated
+22 -1
View File
@@ -40,7 +40,28 @@
"root": {
"inputs": {
"home-manager": "home-manager",
"nixpkgs": "nixpkgs"
"nixpkgs": "nixpkgs",
"sops-nix": "sops-nix"
}
},
"sops-nix": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1791103873,
"narHash": "sha256-nFxM+pKoZ8LJAEnUXARyCaOAloWgaW9kZQOSjWzKcTE=",
"owner": "Mic92",
"repo": "sops-nix",
"rev": "dcd241ba97088c22569d1573286e1b9daad340c0",
"type": "github"
},
"original": {
"owner": "Mic92",
"repo": "sops-nix",
"type": "github"
}
}
},
+7 -1
View File
@@ -8,14 +8,20 @@
url = "github:nix-community/home-manager/release-26.05";
inputs.nixpkgs.follows = "nixpkgs";
};
sops-nix = {
url = "github:Mic92/sops-nix";
inputs.nixpkgs.follows = "nixpkgs";
};
};
outputs = { self, nixpkgs, home-manager, ... }: {
outputs = { self, nixpkgs, home-manager, sops-nix, ... }: {
nixosConfigurations.la2410 = nixpkgs.lib.nixosSystem {
system = "x86_64-linux";
modules = [
./hosts/la2410/configuration.nix
sops-nix.nixosModules.sops
home-manager.nixosModules.home-manager
{
+14 -1
View File
@@ -63,7 +63,20 @@ services.blueman.enable = true;
10.0.1.22 piped.shihaam.me pipedapi.shihaam.me pipedproxy.shihaam.me typetype.shihaam.me
10.0.1.3 mapmaker.sarlink.net
10.0.1.16 git.shihaam.dev
'' + builtins.readFile ./private-hosts;
'';
# Private entries live sops-encrypted in secrets.yaml (public repo) and only
# exist at activation time, so /etc/hosts is rendered by sops-nix from the
# normal build-time hosts plus the decrypted secret. Decrypted with the
# openssh host key, which sops-nix picks up automatically.
sops.defaultSopsFile = ./secrets.yaml;
sops.secrets.private-hosts = { };
sops.templates.hosts = {
file = pkgs.concatText "hosts-template" (config.networking.hostFiles ++ [
(pkgs.writeText "private-hosts" config.sops.placeholder.private-hosts)
]);
mode = "0444";
};
environment.etc.hosts.source = lib.mkForce config.sops.templates.hosts.path;
nixpkgs.config.allowUnfree = true;
nix.settings.experimental-features = [ "nix-command" "flakes" ];
-1
View File
@@ -1 +0,0 @@
# local-only /etc/hosts entries (skip-worktree, edits stay uncommitted)
+16
View File
@@ -0,0 +1,16 @@
private-hosts: ENC[AES256_GCM,data:yTpnsDRBL1+1nkg+E1lAozj0+a4clFcQbXeNikVM84bARjraGBJvWnn4nqrRt5ewHTo1NjW2p6bMgNWecKk=,iv:77utmMJO8AnkfZcHkS+Ib/KWprXXeppOtYkuXYNKaJg=,tag:wY//E1bf9eBTrdKA/ByKjw==,type:str]
sops:
age:
- enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA0T1VwODVIdTh3cnpXdnhN
dEh3cXMwOFB3ZXA3aFFWWkphc1JtVlQ4cTJrCjVlL2Z0VXg0T05EcTJ3R3VjSStP
elRYa01DWmtpRC9POGhQSG1xaHgyMVUKLS0tIDlFMFlLSUhub3ZkRDZvc0Qwb0N0
OUV6M2Zaem5HenN1UXRMaE1Kb01tbjAKmEruQd8swPclaXBCB46CKWn35G3zqaDz
i9yOg0+t3NMcg7Vm81zHo+KYK/LHhhvBD7w3q0ub7JHTSup77m9LNg==
-----END AGE ENCRYPTED FILE-----
recipient: age1q7nppjnvr4ejgeqrlx08z7leyzarvn83fdp87p4wwy0sgdmspddqufv0ak
lastmodified: "2026-10-06T01:03:55Z"
mac: ENC[AES256_GCM,data:Gn2jpvfkZZwNH3tWpf0rA6/GIVAtgzVx9bRFVtzdNTbK1XKCjth8XA+BChwBu1gtAWehUIobchfZqevwt89KiF5T4Zi5ElDM2emaJM20RMCEC5GTqsIVAE/kRn+Ld1XU8gT05L5nk7Cnes4khjbPCJMI+l5/6QBCYijB4T2KWn4=,iv:rIlZ159IDoe8rqwywbFlXfiVfrLaTawVv/vEDPn0cGc=,tag:xMGcL+fJflcPY0i03OkrVQ==,type:str]
unencrypted_suffix: _unencrypted
version: 3.13.3