From 163c7e5f7206c6def433270ee704490cc7c76713 Mon Sep 17 00:00:00 2001 From: Shihaam Abdul Rahman Date: Tue, 6 Oct 2026 06:40:37 +0500 Subject: [PATCH] sops on hosts file --- .gitignore | 3 ++ .sops.yaml | 7 +++ README.md | 92 +++++++++++++++++++++++++++++++++- flake.lock | 23 ++++++++- flake.nix | 8 ++- hosts/la2410/configuration.nix | 15 +++++- hosts/la2410/private-hosts | 1 - hosts/la2410/secrets.yaml | 16 ++++++ 8 files changed, 160 insertions(+), 5 deletions(-) create mode 100644 .sops.yaml delete mode 100644 hosts/la2410/private-hosts create mode 100644 hosts/la2410/secrets.yaml diff --git a/.gitignore b/.gitignore index 2f8c505..1117348 100644 --- a/.gitignore +++ b/.gitignore @@ -1,3 +1,6 @@ # nixos-rebuild build / nix build output symlinks result result-* + +# local-only /etc/hosts entries, kept out of this public repo +hosts/la2410/private-hosts diff --git a/.sops.yaml b/.sops.yaml new file mode 100644 index 0000000..f8d26de --- /dev/null +++ b/.sops.yaml @@ -0,0 +1,7 @@ +keys: + - &la2410 age1q7nppjnvr4ejgeqrlx08z7leyzarvn83fdp87p4wwy0sgdmspddqufv0ak +creation_rules: + - path_regex: hosts/la2410/secrets\.yaml$ + key_groups: + - age: + - *la2410 diff --git a/README.md b/README.md index 008482c..62f42b1 100644 --- a/README.md +++ b/README.md @@ -1,3 +1,93 @@ # dotfiles -~/.config and some config for my linux box \ No newline at end of file +~/.config and some config for my linux box + +NixOS + home-manager flake for `la2410`. All commands below run from the repo root: + +```bash +cd ~/git/sargit/dotfiles +``` + +## Apply changes + +```bash +doas nixos-rebuild switch --flake .#la2410 +``` + +New files must be `git add`ed first, or the flake can't see them. + +Other modes: + +```bash +doas nixos-rebuild test --flake .#la2410 # activate now, but don't add a boot entry +doas nixos-rebuild boot --flake .#la2410 # only use it from the next boot +nixos-rebuild build --flake .#la2410 # just build it, leaves ./result +``` + +## Update + +```bash +nix flake update # bump all inputs (nixpkgs, home-manager, sops-nix) +nix flake update nixpkgs # bump just one +doas nixos-rebuild switch --flake .#la2410 +git commit flake.lock -m "update" +``` + +Run `nix flake update` as yourself, not with doas, so `flake.lock` stays owned by you. + +To move to a new NixOS release (e.g. 26.11), change the `nixos-26.05` and `release-26.05` branches in `flake.nix`, then update as above. Leave `system.stateVersion` alone. + +## Roll back + +```bash +doas nixos-rebuild switch --rollback +nixos-rebuild list-generations +``` + +Or pick an older generation in the GRUB menu at boot. + +## Clean up + +```bash +doas nix-collect-garbage --delete-older-than 14d +nix-collect-garbage --delete-older-than 14d # your user profile +nix store optimise +``` + +## Find and try packages + +```bash +nix search nixpkgs +nix shell nixpkgs# # temporary shell with it +nix run nixpkgs# # run it once +``` + +To install a package permanently, add it to `environment.systemPackages` in `hosts/la2410/configuration.nix` and rebuild. + +## Private /etc/hosts entries (sops) + +Private hosts are stored encrypted in `hosts/la2410/secrets.yaml`, decrypted with the machine's SSH host key. Public ones go straight into `networking.extraHosts`. + +Edit them: + +```bash +doas env SOPS_AGE_KEY_CMD="nix run nixpkgs#ssh-to-age -- -private-key -i /etc/ssh/ssh_host_ed25519_key" \ + nix run nixpkgs#sops -- hosts/la2410/secrets.yaml +``` + +Add lines under `private-hosts: |`, save, then rebuild. + +If the SSH host key ever changes (reinstall), get the new age key, put it in `.sops.yaml`, and re-encrypt with the old key still available: + +```bash +nix run nixpkgs#ssh-to-age -- -i /etc/ssh/ssh_host_ed25519_key.pub +doas env SOPS_AGE_KEY_CMD="..." nix run nixpkgs#sops -- updatekeys hosts/la2410/secrets.yaml +``` + +## Debugging a failed build + +```bash +doas nixos-rebuild switch --flake .#la2410 --show-trace +journalctl -b -p err # errors this boot +systemctl --failed +``` diff --git a/flake.lock b/flake.lock index 536e810..9f88644 100644 --- a/flake.lock +++ b/flake.lock @@ -40,7 +40,28 @@ "root": { "inputs": { "home-manager": "home-manager", - "nixpkgs": "nixpkgs" + "nixpkgs": "nixpkgs", + "sops-nix": "sops-nix" + } + }, + "sops-nix": { + "inputs": { + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1791103873, + "narHash": "sha256-nFxM+pKoZ8LJAEnUXARyCaOAloWgaW9kZQOSjWzKcTE=", + "owner": "Mic92", + "repo": "sops-nix", + "rev": "dcd241ba97088c22569d1573286e1b9daad340c0", + "type": "github" + }, + "original": { + "owner": "Mic92", + "repo": "sops-nix", + "type": "github" } } }, diff --git a/flake.nix b/flake.nix index ad4e03e..811a06a 100644 --- a/flake.nix +++ b/flake.nix @@ -8,14 +8,20 @@ url = "github:nix-community/home-manager/release-26.05"; inputs.nixpkgs.follows = "nixpkgs"; }; + + sops-nix = { + url = "github:Mic92/sops-nix"; + inputs.nixpkgs.follows = "nixpkgs"; + }; }; - outputs = { self, nixpkgs, home-manager, ... }: { + outputs = { self, nixpkgs, home-manager, sops-nix, ... }: { nixosConfigurations.la2410 = nixpkgs.lib.nixosSystem { system = "x86_64-linux"; modules = [ ./hosts/la2410/configuration.nix + sops-nix.nixosModules.sops home-manager.nixosModules.home-manager { diff --git a/hosts/la2410/configuration.nix b/hosts/la2410/configuration.nix index 1de1d17..a7fc2b2 100644 --- a/hosts/la2410/configuration.nix +++ b/hosts/la2410/configuration.nix @@ -63,7 +63,20 @@ services.blueman.enable = true; 10.0.1.22 piped.shihaam.me pipedapi.shihaam.me pipedproxy.shihaam.me typetype.shihaam.me 10.0.1.3 mapmaker.sarlink.net 10.0.1.16 git.shihaam.dev - '' + builtins.readFile ./private-hosts; + ''; + # Private entries live sops-encrypted in secrets.yaml (public repo) and only + # exist at activation time, so /etc/hosts is rendered by sops-nix from the + # normal build-time hosts plus the decrypted secret. Decrypted with the + # openssh host key, which sops-nix picks up automatically. + sops.defaultSopsFile = ./secrets.yaml; + sops.secrets.private-hosts = { }; + sops.templates.hosts = { + file = pkgs.concatText "hosts-template" (config.networking.hostFiles ++ [ + (pkgs.writeText "private-hosts" config.sops.placeholder.private-hosts) + ]); + mode = "0444"; + }; + environment.etc.hosts.source = lib.mkForce config.sops.templates.hosts.path; nixpkgs.config.allowUnfree = true; nix.settings.experimental-features = [ "nix-command" "flakes" ]; diff --git a/hosts/la2410/private-hosts b/hosts/la2410/private-hosts deleted file mode 100644 index 2947f6d..0000000 --- a/hosts/la2410/private-hosts +++ /dev/null @@ -1 +0,0 @@ -# local-only /etc/hosts entries (skip-worktree, edits stay uncommitted) diff --git a/hosts/la2410/secrets.yaml b/hosts/la2410/secrets.yaml new file mode 100644 index 0000000..18f5909 --- /dev/null +++ b/hosts/la2410/secrets.yaml @@ -0,0 +1,16 @@ +private-hosts: ENC[AES256_GCM,data:yTpnsDRBL1+1nkg+E1lAozj0+a4clFcQbXeNikVM84bARjraGBJvWnn4nqrRt5ewHTo1NjW2p6bMgNWecKk=,iv:77utmMJO8AnkfZcHkS+Ib/KWprXXeppOtYkuXYNKaJg=,tag:wY//E1bf9eBTrdKA/ByKjw==,type:str] +sops: + age: + - enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA0T1VwODVIdTh3cnpXdnhN + dEh3cXMwOFB3ZXA3aFFWWkphc1JtVlQ4cTJrCjVlL2Z0VXg0T05EcTJ3R3VjSStP + elRYa01DWmtpRC9POGhQSG1xaHgyMVUKLS0tIDlFMFlLSUhub3ZkRDZvc0Qwb0N0 + OUV6M2Zaem5HenN1UXRMaE1Kb01tbjAKmEruQd8swPclaXBCB46CKWn35G3zqaDz + i9yOg0+t3NMcg7Vm81zHo+KYK/LHhhvBD7w3q0ub7JHTSup77m9LNg== + -----END AGE ENCRYPTED FILE----- + recipient: age1q7nppjnvr4ejgeqrlx08z7leyzarvn83fdp87p4wwy0sgdmspddqufv0ak + lastmodified: "2026-10-06T01:03:55Z" + mac: ENC[AES256_GCM,data:Gn2jpvfkZZwNH3tWpf0rA6/GIVAtgzVx9bRFVtzdNTbK1XKCjth8XA+BChwBu1gtAWehUIobchfZqevwt89KiF5T4Zi5ElDM2emaJM20RMCEC5GTqsIVAE/kRn+Ld1XU8gT05L5nk7Cnes4khjbPCJMI+l5/6QBCYijB4T2KWn4=,iv:rIlZ159IDoe8rqwywbFlXfiVfrLaTawVv/vEDPn0cGc=,tag:xMGcL+fJflcPY0i03OkrVQ==,type:str] + unencrypted_suffix: _unencrypted + version: 3.13.3