sops: 配置多机器标准密钥流程

This commit is contained in:
2026-05-17 12:14:00 +08:00
parent 77892cff01
commit 153bd77227
3 changed files with 22 additions and 10 deletions
+5 -5
View File
@@ -4,9 +4,9 @@
imports =
[
./hardware-configuration.nix
inputs.sops-nix.nixosModules.sops
../modules/nix-cache.nix
../modules/users/origami.nix
../modules/sops.nix
];
# BIOS + GRUB, 安装到 MBR
@@ -83,11 +83,11 @@
users.users.origami.extraGroups = [ "wheel" ];
security.sudo.wheelNeedsPassword = false;
sops.defaultSopsFile = ../../secrets/ssh-private.yaml;
sops.defaultSopsFormat = "yaml";
sops.age.keyFile = "/home/origami/.config/sops/age/keys.txt";
services.openssh.enable = true;
# 密钥管理: 这是对外机器
sops.defaultSopsFile = ../../secrets/hosts/oparic-local-dev.yaml;
sops.age.keyFile = "/var/lib/sops/age/keys.txt";
system.stateVersion = "23.11";
}