2024-06-20 08:59:56 -05:00
|
|
|
---
|
|
|
|
# config files for sops & used for encrypting keys that sops-nix decrypts.
|
2024-07-06 14:53:08 -05:00
|
|
|
# each machine key is derived from its generated `ssh_hosts_ed` file
|
2024-06-20 08:59:56 -05:00
|
|
|
# via ssh-to-age
|
|
|
|
# sops encrypts the secrets ready to decrypt with the private key of any of the below machines
|
|
|
|
# OR my 'main' key thats kept outside this repo securely.
|
|
|
|
|
|
|
|
# key-per-machine is a little more secure and a little more work than
|
|
|
|
# copying one key to each machine
|
|
|
|
|
|
|
|
keys:
|
|
|
|
- users:
|
|
|
|
- &jahanson age18kj3xhlvgjeg2awwku3r8d95w360uysu0w5ejghnp4kh8qmtge5qwa2vjp
|
|
|
|
- hosts:
|
|
|
|
- &durincore age1d9p83j52m2xg0vh9k7q0uwlxwhs3y6tlv68yg9s2h9mdw2fmmsqshddz5m
|
2024-07-14 06:29:05 -05:00
|
|
|
- &gandalf age1m83ups8xn2jy4ayr8gw0pyn34smr0huqc5v76e4887az4vsl4yzsj0dlhd
|
2024-07-01 13:56:23 -05:00
|
|
|
- &legiondary age1lp6rrlvmytp9ka6q89m0e0am26222kwrn7aqd45hu07s3a6jv3gqty86eu
|
2024-07-07 12:47:55 -05:00
|
|
|
- &telperion age1nwnqxjuaxlt5g7fe8rnspvn2c36uuef4hzwuwa6cfjfalz2lrd4q4n5fpl
|
2024-06-20 08:59:56 -05:00
|
|
|
- &varda age1a8z3p24v32l9yxm5z2l8h7rpc3nhacyfv4jvetk2lenrvsdstd3sdu2kaf
|
|
|
|
|
|
|
|
|
|
|
|
creation_rules:
|
|
|
|
- path_regex: .*\.sops\.yaml$
|
|
|
|
key_groups:
|
|
|
|
- age:
|
|
|
|
- *durincore
|
|
|
|
- *gandalf
|
|
|
|
- *jahanson
|
2024-06-21 14:15:45 -05:00
|
|
|
- *legiondary
|
2024-06-20 08:59:56 -05:00
|
|
|
- *telperion
|
|
|
|
- *varda
|