This commit is contained in:
Lauren Lagarde 2025-08-22 00:27:48 -05:00
parent 50ac8fc6e0
commit 23c356697c

View file

@ -18,7 +18,7 @@ in {
};
time.timeZone = "America/Chicago";
sops.defaultSopsFile = ../../secrets.yaml;
sops.defaultSopsFile = ./secrets.yaml;
imports = [
inputs.sops-nix.nixosModules.sops
@ -37,7 +37,7 @@ in {
../../nixos/tweaks/systemd-resolved_nonsense.nix
# Dotspace
../../dotspace/configuration.nix
../../dotspace/parts/tinc.nix
# Users
../../users/lauren_lagarde/configuration.nix
@ -67,18 +67,18 @@ in {
##############################################################################
# Tinc
sops.secrets."dotspace/${hostName}/keys/tinc/rsa_key.priv" = { sopsFile = ./secrets.yaml; };
sops.secrets."dotspace/${hostName}/keys/tinc/ed25519_key.priv" = { sopsFile = ./secrets.yaml; };
sops.secrets."dotspace/outpost/keys/tinc/rsa_key.priv" = { sopsFile = ./secrets.yaml; };
sops.secrets."dotspace/outpost/keys/tinc/ed25519_key.priv" = { sopsFile = ./secrets.yaml; };
systemd.network.networks."90-tinc" = {
matchConfig.Name = "tinc.dotspace";
address = [ "${tinc-ip}/32" ];
address = [ "10.86.84.106/32" ];
routes = [ { Destination = "10.86.84.0/24"; } ];
};
services.tinc.networks.dotspace = {
name = hostName;
ed25519PrivateKeyFile = "/run/secrets/dotspace/${hostName}/keys/tinc/ed25519_key.priv";
ed25519PrivateKeyFile = "/run/secrets/dotspace/outpost/keys/tinc/ed25519_key.priv";
chroot = false;
settings.ConnectTo = [ "fortress" ];