nix/hosts/marvin/secrets/secrets.nix

29 lines
2.9 KiB
Nix

let
yubi-back = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDTVGi3PItsbUhFgnFZlqo1iUggL4npMg94+9FsyhEPfShcQwJK2/jJzjv5S9KPuk3cY7aoqyVFLbnasSBZPXmscJmOiVNvtWvHoC3QPXvf3IAcVZ5KOLpY2NJlPx/pAb31C6ewtg8v3VlyhL4zEp6M+AGwXX51tFDh2GnYD+7SNF+aMhKCrX63syAhgPy3F8mZ2RIDLAu+lsYlwdpWRkSEv9kcjX/6+3QgUWjfPBaKEeYID22ihSuj7+AiuAt0gM4q0TY/Hpcx+qDLonrIuBnm1hMZDgbv//D0sHIUxJQkGTKTEbkZxoh0Qri7UV/V6l3mETaG40deuemMU7RFY7Khl8RajNZ+9z0FdquS/HCt8+fYQk6eLneJrMIQ1bI4awrtblG3P2Yf2QUu+H3kfCQe44R3WjUugTbNtumVgyQBzl2dzlIVn1pZBeyZy70XCgbaFKkDR8Y/qZiUoZ0afP3vTOXhkn5UBfutTKwUiSGh3S8Ge5YhNgKHWE2eQp1ckEm0IMJV/q5Nsw/yBBXj/kfD8ekz96LQ+gP5JFLq4EaipXI7FM4aZNOBUZU1l/sCEuq7m997nrBucTKqGm7Ho3rq7bgdj4f6GyUJXSMOM1cN61LLrRumZGGTH8WghVL7ligxZyNFcQoudR8jfpf4mrgRxipQOe1A2umvuufMr+l/bw==";
yubi-main = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBBsOIMMZVmleClXfqUMrnmyh8PFuyiJqHKEZ51Xy746";
backup = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCyTiGctsHaTUlRJn2XQ/745dD0UWGWO8W0en8J5rf7BLI8lL/hPUmbNt45vC5754LXcBjnp1t/1FNgiGhvNZIWJpC+elBmhyMhg8z1exRZPD+as7XaH7scnij2vSbSphQFUqH433ggAGe77x5bc7wKFp9n7vj8G1u0JJxMEe1M7kNFY0+ShNtaHna3LxiQOVcW7qVlNKZP8Ol1V7kZLblRADCJMTYOXDIbktA8bbGRfGhbNjJGkL665qz36haYwb2i6A4sC7Y583N8ro8hIDG/ByJqwbl/Sz4rSxkT6G4+OdBvS6sa7TovNXHjmQCculMIltdog7UhgyBsim1sTzxAen3YyFRi1Cz/kLM0oH39m/W4IoMvJcNZCJ3ItLgy+lEVMd87jVOqfuq/hyjHVI0wJtU2Si2HTxv7aKL8gPzqXwbNH+nhkhlQ0ZH8zKVBunOgLDgsmGIky5X/T3bpWZpIoFkOR7AYrId/5dOeGM3pHhHb6woZ3SRubZ43Ah/VdJM=";
me = [yubi-main yubi-back backup];
marvin = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIP60B1IOdfJRrDcCKajMV8YJNC01gSsccZi3DKHlS6YJ";
in {
"authentik-env.age".publicKeys = [ marvin yubi-main yubi-back ];
"cf-dyndns-token.age".publicKeys = [ marvin yubi-main yubi-back ];
"cloudflare-ca.age".publicKeys = [ marvin yubi-main yubi-back ];
"cloudflared-creds.age".publicKeys = [ marvin yubi-main yubi-back ];
"cloudflared-vars.age".publicKeys = [ marvin yubi-main yubi-back ];
"external-wg-priv-key.age".publicKeys = [ marvin yubi-main yubi-back ];
"gitea-db-pw.age".publicKeys = [ marvin yubi-main yubi-back ];
"gitea-mail-pw.age".publicKeys = [ marvin yubi-main yubi-back ];
"miniflux-admin.age".publicKeys = [ marvin yubi-main yubi-back ];
"miniflux-oidc-secret.age".publicKeys = [ marvin yubi-main yubi-back ];
"nix-serve-priv.age".publicKeys = [ marvin yubi-main yubi-back ];
"ory-hydra-secret-vars.age".publicKeys = [ marvin yubi-main yubi-back ];
"step-inter-ca-crt.age".publicKeys = [ marvin yubi-main yubi-back ];
"step-inter-ca-key.age".publicKeys = [ marvin yubi-main yubi-back ];
"step-password.age".publicKeys = [ marvin yubi-main yubi-back ];
"step-root-ca-crt.age".publicKeys = [ marvin yubi-main yubi-back ];
"step-root-ca-key.age".publicKeys = [ marvin yubi-main yubi-back ];
"thehedgehog-key.age".publicKeys = [ marvin yubi-main yubi-back ];
"thehedgehog-pem.age".publicKeys = [ marvin yubi-main yubi-back ];
"vaultwarden-vars.age".publicKeys = [ marvin yubi-main yubi-back ];
"vikunja-env.age".publicKeys = [ marvin yubi-main yubi-back ];
}