This commit is contained in:
2026-06-15 19:22:58 +09:00
parent ee0fe4c1b4
commit 33e5f0ae7c
11 changed files with 171 additions and 3 deletions
+2
View File
@@ -13,7 +13,9 @@
./nix.nix
./power.nix
./secure-boot.nix
./sops.nix
./user
./version.nix
./secret.nix
];
}
+14
View File
@@ -0,0 +1,14 @@
_:
let
commonSyetemSecrets = ../../secrets/common/system.yaml;
in
{
sops.secrets = {
"users/moons/hashedPassword" = {
sopsFile = commonSyetemSecrets;
# need before user creation
neededForUsers = true;
};
};
}
+41
View File
@@ -0,0 +1,41 @@
{
inputs,
pkgs,
...
}:
{
imports = [
inputs.sops-nix.nixosModules.sops
];
environment.systemPackages = with pkgs; [
# sops / age
sops
age
ssh-to-age
# YubiKey edit key
age-plugin-yubikey
yubikey-manager
pcsc-tools
# password hash generation
mkpasswd
];
# age-plugin-yubikey depend
services.pcscd.enable = true;
services.openssh.enable = true;
sops = {
defaultSopsFormat = "yaml";
age = {
# system keys
sshKeyPaths = [
"/etc/ssh/ssh_host_ed25519_key"
];
};
};
}
+8 -1
View File
@@ -1,8 +1,15 @@
{ pkgs, ... }:
{
pkgs,
config,
...
}:
{
users.mutableUsers = false;
users.users.moons = {
isNormalUser = true;
description = "moons-14";
hashedPasswordFile = config.sops.secrets."users/moons/hashedPassword".path;
extraGroups = [
"adbusers"
"docker"