sops on hosts file
This commit is contained in:
@@ -1,3 +1,6 @@
|
||||
# nixos-rebuild build / nix build output symlinks
|
||||
result
|
||||
result-*
|
||||
|
||||
# local-only /etc/hosts entries, kept out of this public repo
|
||||
hosts/la2410/private-hosts
|
||||
|
||||
@@ -0,0 +1,7 @@
|
||||
keys:
|
||||
- &la2410 age1q7nppjnvr4ejgeqrlx08z7leyzarvn83fdp87p4wwy0sgdmspddqufv0ak
|
||||
creation_rules:
|
||||
- path_regex: hosts/la2410/secrets\.yaml$
|
||||
key_groups:
|
||||
- age:
|
||||
- *la2410
|
||||
@@ -1,3 +1,93 @@
|
||||
# dotfiles
|
||||
|
||||
~/.config and some config for my linux box
|
||||
~/.config and some config for my linux box
|
||||
|
||||
NixOS + home-manager flake for `la2410`. All commands below run from the repo root:
|
||||
|
||||
```bash
|
||||
cd ~/git/sargit/dotfiles
|
||||
```
|
||||
|
||||
## Apply changes
|
||||
|
||||
```bash
|
||||
doas nixos-rebuild switch --flake .#la2410
|
||||
```
|
||||
|
||||
New files must be `git add`ed first, or the flake can't see them.
|
||||
|
||||
Other modes:
|
||||
|
||||
```bash
|
||||
doas nixos-rebuild test --flake .#la2410 # activate now, but don't add a boot entry
|
||||
doas nixos-rebuild boot --flake .#la2410 # only use it from the next boot
|
||||
nixos-rebuild build --flake .#la2410 # just build it, leaves ./result
|
||||
```
|
||||
|
||||
## Update
|
||||
|
||||
```bash
|
||||
nix flake update # bump all inputs (nixpkgs, home-manager, sops-nix)
|
||||
nix flake update nixpkgs # bump just one
|
||||
doas nixos-rebuild switch --flake .#la2410
|
||||
git commit flake.lock -m "update"
|
||||
```
|
||||
|
||||
Run `nix flake update` as yourself, not with doas, so `flake.lock` stays owned by you.
|
||||
|
||||
To move to a new NixOS release (e.g. 26.11), change the `nixos-26.05` and `release-26.05` branches in `flake.nix`, then update as above. Leave `system.stateVersion` alone.
|
||||
|
||||
## Roll back
|
||||
|
||||
```bash
|
||||
doas nixos-rebuild switch --rollback
|
||||
nixos-rebuild list-generations
|
||||
```
|
||||
|
||||
Or pick an older generation in the GRUB menu at boot.
|
||||
|
||||
## Clean up
|
||||
|
||||
```bash
|
||||
doas nix-collect-garbage --delete-older-than 14d
|
||||
nix-collect-garbage --delete-older-than 14d # your user profile
|
||||
nix store optimise
|
||||
```
|
||||
|
||||
## Find and try packages
|
||||
|
||||
```bash
|
||||
nix search nixpkgs <name>
|
||||
nix shell nixpkgs#<pkg> # temporary shell with it
|
||||
nix run nixpkgs#<pkg> # run it once
|
||||
```
|
||||
|
||||
To install a package permanently, add it to `environment.systemPackages` in `hosts/la2410/configuration.nix` and rebuild.
|
||||
|
||||
## Private /etc/hosts entries (sops)
|
||||
|
||||
Private hosts are stored encrypted in `hosts/la2410/secrets.yaml`, decrypted with the machine's SSH host key. Public ones go straight into `networking.extraHosts`.
|
||||
|
||||
Edit them:
|
||||
|
||||
```bash
|
||||
doas env SOPS_AGE_KEY_CMD="nix run nixpkgs#ssh-to-age -- -private-key -i /etc/ssh/ssh_host_ed25519_key" \
|
||||
nix run nixpkgs#sops -- hosts/la2410/secrets.yaml
|
||||
```
|
||||
|
||||
Add lines under `private-hosts: |`, save, then rebuild.
|
||||
|
||||
If the SSH host key ever changes (reinstall), get the new age key, put it in `.sops.yaml`, and re-encrypt with the old key still available:
|
||||
|
||||
```bash
|
||||
nix run nixpkgs#ssh-to-age -- -i /etc/ssh/ssh_host_ed25519_key.pub
|
||||
doas env SOPS_AGE_KEY_CMD="..." nix run nixpkgs#sops -- updatekeys hosts/la2410/secrets.yaml
|
||||
```
|
||||
|
||||
## Debugging a failed build
|
||||
|
||||
```bash
|
||||
doas nixos-rebuild switch --flake .#la2410 --show-trace
|
||||
journalctl -b -p err # errors this boot
|
||||
systemctl --failed
|
||||
```
|
||||
|
||||
Generated
+22
-1
@@ -40,7 +40,28 @@
|
||||
"root": {
|
||||
"inputs": {
|
||||
"home-manager": "home-manager",
|
||||
"nixpkgs": "nixpkgs"
|
||||
"nixpkgs": "nixpkgs",
|
||||
"sops-nix": "sops-nix"
|
||||
}
|
||||
},
|
||||
"sops-nix": {
|
||||
"inputs": {
|
||||
"nixpkgs": [
|
||||
"nixpkgs"
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1791103873,
|
||||
"narHash": "sha256-nFxM+pKoZ8LJAEnUXARyCaOAloWgaW9kZQOSjWzKcTE=",
|
||||
"owner": "Mic92",
|
||||
"repo": "sops-nix",
|
||||
"rev": "dcd241ba97088c22569d1573286e1b9daad340c0",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "Mic92",
|
||||
"repo": "sops-nix",
|
||||
"type": "github"
|
||||
}
|
||||
}
|
||||
},
|
||||
|
||||
@@ -8,14 +8,20 @@
|
||||
url = "github:nix-community/home-manager/release-26.05";
|
||||
inputs.nixpkgs.follows = "nixpkgs";
|
||||
};
|
||||
|
||||
sops-nix = {
|
||||
url = "github:Mic92/sops-nix";
|
||||
inputs.nixpkgs.follows = "nixpkgs";
|
||||
};
|
||||
};
|
||||
|
||||
outputs = { self, nixpkgs, home-manager, ... }: {
|
||||
outputs = { self, nixpkgs, home-manager, sops-nix, ... }: {
|
||||
nixosConfigurations.la2410 = nixpkgs.lib.nixosSystem {
|
||||
system = "x86_64-linux";
|
||||
|
||||
modules = [
|
||||
./hosts/la2410/configuration.nix
|
||||
sops-nix.nixosModules.sops
|
||||
|
||||
home-manager.nixosModules.home-manager
|
||||
{
|
||||
|
||||
@@ -63,7 +63,20 @@ services.blueman.enable = true;
|
||||
10.0.1.22 piped.shihaam.me pipedapi.shihaam.me pipedproxy.shihaam.me typetype.shihaam.me
|
||||
10.0.1.3 mapmaker.sarlink.net
|
||||
10.0.1.16 git.shihaam.dev
|
||||
'' + builtins.readFile ./private-hosts;
|
||||
'';
|
||||
# Private entries live sops-encrypted in secrets.yaml (public repo) and only
|
||||
# exist at activation time, so /etc/hosts is rendered by sops-nix from the
|
||||
# normal build-time hosts plus the decrypted secret. Decrypted with the
|
||||
# openssh host key, which sops-nix picks up automatically.
|
||||
sops.defaultSopsFile = ./secrets.yaml;
|
||||
sops.secrets.private-hosts = { };
|
||||
sops.templates.hosts = {
|
||||
file = pkgs.concatText "hosts-template" (config.networking.hostFiles ++ [
|
||||
(pkgs.writeText "private-hosts" config.sops.placeholder.private-hosts)
|
||||
]);
|
||||
mode = "0444";
|
||||
};
|
||||
environment.etc.hosts.source = lib.mkForce config.sops.templates.hosts.path;
|
||||
|
||||
nixpkgs.config.allowUnfree = true;
|
||||
nix.settings.experimental-features = [ "nix-command" "flakes" ];
|
||||
|
||||
@@ -1 +0,0 @@
|
||||
# local-only /etc/hosts entries (skip-worktree, edits stay uncommitted)
|
||||
@@ -0,0 +1,16 @@
|
||||
private-hosts: ENC[AES256_GCM,data:yTpnsDRBL1+1nkg+E1lAozj0+a4clFcQbXeNikVM84bARjraGBJvWnn4nqrRt5ewHTo1NjW2p6bMgNWecKk=,iv:77utmMJO8AnkfZcHkS+Ib/KWprXXeppOtYkuXYNKaJg=,tag:wY//E1bf9eBTrdKA/ByKjw==,type:str]
|
||||
sops:
|
||||
age:
|
||||
- enc: |
|
||||
-----BEGIN AGE ENCRYPTED FILE-----
|
||||
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA0T1VwODVIdTh3cnpXdnhN
|
||||
dEh3cXMwOFB3ZXA3aFFWWkphc1JtVlQ4cTJrCjVlL2Z0VXg0T05EcTJ3R3VjSStP
|
||||
elRYa01DWmtpRC9POGhQSG1xaHgyMVUKLS0tIDlFMFlLSUhub3ZkRDZvc0Qwb0N0
|
||||
OUV6M2Zaem5HenN1UXRMaE1Kb01tbjAKmEruQd8swPclaXBCB46CKWn35G3zqaDz
|
||||
i9yOg0+t3NMcg7Vm81zHo+KYK/LHhhvBD7w3q0ub7JHTSup77m9LNg==
|
||||
-----END AGE ENCRYPTED FILE-----
|
||||
recipient: age1q7nppjnvr4ejgeqrlx08z7leyzarvn83fdp87p4wwy0sgdmspddqufv0ak
|
||||
lastmodified: "2026-10-06T01:03:55Z"
|
||||
mac: ENC[AES256_GCM,data:Gn2jpvfkZZwNH3tWpf0rA6/GIVAtgzVx9bRFVtzdNTbK1XKCjth8XA+BChwBu1gtAWehUIobchfZqevwt89KiF5T4Zi5ElDM2emaJM20RMCEC5GTqsIVAE/kRn+Ld1XU8gT05L5nk7Cnes4khjbPCJMI+l5/6QBCYijB4T2KWn4=,iv:rIlZ159IDoe8rqwywbFlXfiVfrLaTawVv/vEDPn0cGc=,tag:xMGcL+fJflcPY0i03OkrVQ==,type:str]
|
||||
unencrypted_suffix: _unencrypted
|
||||
version: 3.13.3
|
||||
Reference in New Issue
Block a user