From 24ce17adec26373b0c691eade4b3fb656ec170ba Mon Sep 17 00:00:00 2001 From: Matei Adriel Date: Tue, 18 Jul 2023 15:31:02 +0300 Subject: [PATCH] Rekeyed secrets to include laleptus (also removed spotifyd) --- home/features/desktop/spotifyd/default.nix | 16 -------------- home/features/desktop/spotifyd/password.age | 8 ------- .../desktop/wakatime/wakatime_config.age | 13 ++++++------ .../common/global/wireless/wifi_passwords.age | 20 ++++++++++-------- .../nixos/common/users/adrielus_password.age | Bin 560 -> 614 bytes secrets.nix | 12 ++++++----- 6 files changed, 24 insertions(+), 45 deletions(-) delete mode 100644 home/features/desktop/spotifyd/default.nix delete mode 100644 home/features/desktop/spotifyd/password.age diff --git a/home/features/desktop/spotifyd/default.nix b/home/features/desktop/spotifyd/default.nix deleted file mode 100644 index abf3628..0000000 --- a/home/features/desktop/spotifyd/default.nix +++ /dev/null @@ -1,16 +0,0 @@ -{ config, lib, pkgs, ... }: { - services.spotifyd = { - enable = true; - settings = { - global = { - username = "mjmsimuzc910khmr6yoccgtyr"; - device_name = "nix"; # TODO: perhaps include the hostname here? - password_cmd = - # TODO: move this in it's own module - let identities = builtins.concatStringsSep " " (map (path: "-i ${path}") config.homeage.identityPaths); - in "${lib.getExe pkgs.age} --decrypt ${identities} ${./password.age}"; - }; - }; - }; -} - diff --git a/home/features/desktop/spotifyd/password.age b/home/features/desktop/spotifyd/password.age deleted file mode 100644 index bbe9ffd..0000000 --- a/home/features/desktop/spotifyd/password.age +++ /dev/null @@ -1,8 +0,0 @@ -age-encryption.org/v1 --> ssh-ed25519 UUF9JQ FSx8O2svnwtbQ14eDPxFaBpnnUwx8rZbbzPKbg6yP2c -iZSfXaCF4b3vdpceO6cjdD4e+s+a0wowJJFNflO/JJQ --> _nE-grease ,,1|@ -RtO87gZKvnqPCFUe5XcXgXuIOmMFMrJU7YU ---- dA0HKjUgZYdBU/DF+t6K7oeVu725up4Ve7ya7alP7yk -D$9?|G0>͊|4Z5>e$ -#kDgq \ No newline at end of file diff --git a/home/features/desktop/wakatime/wakatime_config.age b/home/features/desktop/wakatime/wakatime_config.age index 573c5a0..452a0bf 100644 --- a/home/features/desktop/wakatime/wakatime_config.age +++ b/home/features/desktop/wakatime/wakatime_config.age @@ -1,8 +1,7 @@ age-encryption.org/v1 --> ssh-ed25519 UUF9JQ xZrl2Wl0woDhkVrg+1pI+BbWHCg3XV3T7pFoXgedR30 -+/LVZ/HO8Larngohcw1qJlNOrx81U4dUwgZjl3eSr8E --> > ssh-ed25519 UUF9JQ VBRqGf79Jw0ciCQMqgtfcHJJKBLXtFHYFsNMIACcWFw +HPXapSSEJnShJe5N25jQ6HMzuaUgwsPrF+uol2+yA54 +-> .,=H1-grease E ssh-ed25519 UUF9JQ DSej3R3rllWa8hJPGoMZcEIMNb5Fdr2kj3QT2VP4Slg -eq6+W/naFadnfA6iuZ4mLeJA8mIATenivmSPvM0IOdk --> ssh-ed25519 qgVaDQ iXTnXO2YIarah7rk8p2585tdpei6s+xMyr3iZAlmAj0 -M7cBqZZrxnImgcXp6saeBLMPnw3ogmVIOn/NMhRI97Y --> TED-grease z ;"0 [2 G5M -u7n1btlGnv/Qz0jJ ---- eu72XdP32dvM2PHwBp2a8Z5qbN8XuIQpOlWE7VVWN6c -nݑr=|(Ei5 -S=-n#7\+` .3 ՘|IB~2էvi QP_4Ǽ,l6qSdͻ[>k0~lri$r48>X]3eg#9e%lS@f \ No newline at end of file +-> ssh-ed25519 qgVaDQ X59wGhVy2/t73FguLETsah+pqaGei4ymRNOIF+KF7WQ +nBdcTHQYSNA8rhR8FBsT1jCx7oc5UHCSYJOw6fqH14c +-> ssh-ed25519 3gahUA GVCyPuugr3JY9+TSB1PqjoDUy5T+Y/5IaKSnxNQNCwk +TVp38LLUz5IXf7jA1w+B4MUBpeqY1b64l5/rKkUcNv4 +-> ssh-ed25519 UUF9JQ TqslGhrZP5LaNDz0tVlgSnPPsXIWImKrsTTcJ+Bxkz4 +HE9+CcjE3krbP1BOEvFCK0nm380sU9L717PnZYUOCbM +-> xWO"m-grease DUn8[ ^ucb +1wP(\@ +XDAjzkQ7ll4iKEBO88q99cBcai3wuOqeYEk2d407mqoDAAbm2KRwrYpTr6aKpArD +7yax3W5t8Y1PJ3uUEMnr1KhJiSZ0PHB3Ej+dKgL0Og +--- 4wnYq4dm1hZwXh+Z1xiZIabJr7rtXZP63Gemxkmsy0k +ӭ}f>j:m8:ZBs<3GGZ~WW Ct@XP̄b}QFa& HSehz$-X)nJtO)qKFHc1;iFm0Yqnn#l+m!jZ7 zCkNp`5S=Q*iG$mri-UroqX;61INso*AR@?tkM;h7k599VqT!FGd6+nXzZy)fQi?#u zD{vg!MMGb!R1gY|ELo#PxaLUp8Eq@RssuG94aYUj9IGh7Abm7Zz19M(`vv!yCrRc%7iW*tnEQ)DC* z_<-VN$+8I=Z8epe*X}g=xn;UMJAft|Nlr`#<5*65jE+WOw@GxnLnTVomTO8V+Zz&f zyge66)?rPO7>X0&ycNnFs_unlHj#TO4i*;IrMZLCozy97&?o}j>c~Jpn$LDm~dHXqE*83iU|y24l!(8<_X>U2lYtvlcM zcUEHZ|hEz54X-HfpB0#yL(F5dwwpRe?I$SXXW62;{pEdJo~;+EHv@RM!Y--{sJ@H B*Q5Xd delta 534 zcmWm7O>5Ht002;g!6X+?dQ&2+GKi&3+oTDC(4Q3IBKR?3B6#wkr-9-@+{B|WFNzFL;%y*9kBaXPydO(1m+oGg_j)wm;6Z{JcH*;k&~cSYRKV+&y*7wQ7Z(*g%drM)*=S> z%up(FxKU=sY7fX>1B1ZK>RJIoU>saGB&EuOc3*IfE{2!#b6L!xVuh@=F_cZX@wDAc z%GQ9^r!j>3HG$3pkb)$<9BK*{hy=O8c4}N?jJ$Nc!c8QHOl5C6BGHC3)+_(J-X!7q ztl{fQpo5uJP(x>6ShBe5fEQ~Pni|xU63mFvg^<sw#<03TTdgs=8bF~u~nwR z3w1~kiMZHA%4pey`c=dMMr_w?4K*qrO?|w;)$3&1=`qv%|%`C-0UoOZ&TfSA=g5-+Wvw_Ku!@zmY%N z-+jCf|C#Kp-u|_p-g&U|JahAEXQd(k-RgYEUwHQ7_4e_pi_53Ceqs(cBUaA5Jve`O Pvibgz_xqe1Y@7c8!k55a diff --git a/secrets.nix b/secrets.nix index 91cf4d1..f876448 100644 --- a/secrets.nix +++ b/secrets.nix @@ -1,13 +1,15 @@ let - adrielus = builtins.readFile ./hosts/nixos/tethys/id_ed25519.pub; + adrielus_tethys = builtins.readFile ./hosts/nixos/tethys/id_ed25519.pub; tethys = builtins.readFile ./hosts/nixos/tethys/ssh_host_ed25519_key.pub; + lapetus = builtins.readFile ./hosts/nixos/lapetus/ssh_host_ed25519_key.pub; + all_hosts = [ tethys lapetus ]; in { # Scoped for entire systems - "./hosts/nixos/common/global/wireless/wifi_passwords.age".publicKeys = [ adrielus tethys ]; - "./hosts/nixos/common/users/adrielus_password.age".publicKeys = [ adrielus tethys ]; + "./hosts/nixos/common/global/wireless/wifi_passwords.age".publicKeys = all_hosts ++ [ adrielus_tethys ]; + "./hosts/nixos/common/users/adrielus_password.age".publicKeys = all_hosts ++ [ adrielus_tethys ]; # Scoped for the user - "./home/features/desktop/wakatime/wakatime_config.age".publicKeys = [ adrielus ]; - "./home/features/desktop/spotifyd/password.age".publicKeys = [ adrielus ]; + # TODO: move this into `pass`. + "./home/features/desktop/wakatime/wakatime_config.age".publicKeys = [ adrielus_tethys ]; }