Compare commits
2 Commits
604cd9315d
...
15f3bf07e7
Author | SHA1 | Date | |
---|---|---|---|
15f3bf07e7 | |||
10e0ab4813 |
15
flake.lock
generated
15
flake.lock
generated
@ -544,17 +544,14 @@
|
|||||||
"mysecrets": {
|
"mysecrets": {
|
||||||
"flake": false,
|
"flake": false,
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1740942589,
|
"lastModified": 1740938100,
|
||||||
"narHash": "sha256-ND33Zox6hj7DrcjtIEMuAZ7zwToy1iC3hmRjiWQclK4=",
|
"narHash": "sha256-MjcA5IFJq5B7uBO+Bj676txMlsR3NraI13hJ4B9Fz/E=",
|
||||||
"ref": "refs/heads/main",
|
"path": "/home/user/nix-secrets",
|
||||||
"rev": "764a6753bc3e24df936060f7314e9da9a29b06e5",
|
"type": "path"
|
||||||
"revCount": 7,
|
|
||||||
"type": "git",
|
|
||||||
"url": "ssh://gitea@gitea.linerds.us/unexplrd/nix-secrets"
|
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
"type": "git",
|
"path": "/home/user/nix-secrets",
|
||||||
"url": "ssh://gitea@gitea.linerds.us/unexplrd/nix-secrets"
|
"type": "path"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"neve": {
|
"neve": {
|
||||||
|
5
hosts/dunamis/builder.nix
Normal file
5
hosts/dunamis/builder.nix
Normal file
@ -0,0 +1,5 @@
|
|||||||
|
{
|
||||||
|
nix.settings = {
|
||||||
|
secret-key-files = /var/nix/cache-priv-key.pem;
|
||||||
|
};
|
||||||
|
}
|
@ -7,7 +7,10 @@
|
|||||||
sopSec = config.sops.secrets;
|
sopSec = config.sops.secrets;
|
||||||
secrets = inputs.mysecrets;
|
secrets = inputs.mysecrets;
|
||||||
in {
|
in {
|
||||||
nix.settings.trusted-users = ["user"];
|
nix.settings.trusted-users = [
|
||||||
|
"user"
|
||||||
|
"remotebuild"
|
||||||
|
];
|
||||||
users.mutableUsers = false;
|
users.mutableUsers = false;
|
||||||
users.users = {
|
users.users = {
|
||||||
user = {
|
user = {
|
||||||
@ -21,10 +24,14 @@ in {
|
|||||||
"${secrets}/ssh/id_ed25519_eldrid_user.pub"
|
"${secrets}/ssh/id_ed25519_eldrid_user.pub"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
# work = {
|
remotebuild = {
|
||||||
# isNormalUser = true;
|
isNormalUser = true;
|
||||||
# extraGroups = ["video"];
|
createHome = false;
|
||||||
# shell = pkgs.nushell;
|
group = "remotebuild";
|
||||||
# };
|
openssh.authorizedKeys.keyFiles = [
|
||||||
|
"${secrets}/ssh/id_ed25519_eldrid_rmbuild.pub"
|
||||||
|
];
|
||||||
};
|
};
|
||||||
|
};
|
||||||
|
users.groups.remotebuild = {};
|
||||||
}
|
}
|
||||||
|
Reference in New Issue
Block a user