nix/secrets.nix
2025-01-06 15:39:09 +01:00

29 lines
934 B
Nix

let
keys = import ./ssh-keys.nix;
secrets = with keys; {
tailscale-authKey = keys.tailscale-machine;
cloudflare-tegola-apiKey = [ machines.caddy ];
prowlarr-apiKey = [ machines.metrics ];
radarr-apiKey = [ machines.metrics ];
sonarr-apiKey = [ machines.metrics ];
lidarr-apiKey = [ machines.metrics ];
readarr-apiKey = [ machines.metrics ];
bazarr-apiKey = [ machines.metrics ];
grafana-admin-pwd = [ machines.metrics ];
nextcloud-admin-pwd = [ machines.nextcloud ];
vaultwarden-admin-pwd = [ machines.vaultwarden ];
searx-secret = [ machines.search ];
searx-prometheus-secret = [
machines.search
machines.metrics
];
watchtower-secrets = [ machines.portainer ];
};
in
builtins.listToAttrs (
map (secretName: {
name = "secrets/${secretName}.age";
value.publicKeys = secrets."${secretName}" ++ keys.infra-core;
}) (builtins.attrNames secrets)
)