From 83658a0721a62905517fb3635cd0a11c1be8252d Mon Sep 17 00:00:00 2001 From: Ivan Malison Date: Tue, 22 Aug 2023 17:11:37 -0600 Subject: [PATCH] [NixOS] Set up cache server --- nixos/cache-server.nix | 20 ++++++++++++++++++++ nixos/configuration.nix | 1 + nixos/keys.nix | 8 +++++++- nixos/machines/ryzen-shine.nix | 1 + nixos/secrets/cache-priv-key.pem.age | Bin 0 -> 2282 bytes nixos/secrets/cache-pub-key.pem | 1 + nixos/secrets/gpg-keys.age | Bin 5255 -> 5514 bytes nixos/secrets/secrets.nix | 3 ++- 8 files changed, 32 insertions(+), 2 deletions(-) create mode 100644 nixos/cache-server.nix create mode 100644 nixos/secrets/cache-priv-key.pem.age create mode 100644 nixos/secrets/cache-pub-key.pem diff --git a/nixos/cache-server.nix b/nixos/cache-server.nix new file mode 100644 index 00000000..6b6b4ba6 --- /dev/null +++ b/nixos/cache-server.nix @@ -0,0 +1,20 @@ +{ config, makeEnable, ... }: +makeEnable config "modules.cache-server" false { + age.secrets."cache-priv-key.pem".file = ./secrets/cache-priv-key.pem.age; + + services.nix-serve = { + enable = true; + secretKeyFile = config.age.secrets."cache-priv-key.pem".path; + port = 5050; + }; + + services.nginx = { + enable = true; + recommendedProxySettings = true; + virtualHosts = { + "0.0.0.0" = { + locations."/".proxyPass = "http://${config.services.nix-serve.bindAddress}:${toString config.services.nix-serve.port}"; + }; + }; + }; +} diff --git a/nixos/configuration.nix b/nixos/configuration.nix index 198fa725..59813ade 100644 --- a/nixos/configuration.nix +++ b/nixos/configuration.nix @@ -4,6 +4,7 @@ ./android.nix ./base.nix ./cache.nix + ./cache-server.nix ./code.nix ./desktop.nix ./environment.nix diff --git a/nixos/keys.nix b/nixos/keys.nix index 9ca7f632..ba1d36bc 100644 --- a/nixos/keys.nix +++ b/nixos/keys.nix @@ -1,4 +1,9 @@ rec { + hostKeys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIG3UqIYs/NY0okKuiIO+dU2OM7A8vv3b6//GedagvLoX ryzen-shine.local" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINFbM1sL/vlDhrqPV1OMIGi4dKG0tMKhWSXx95ccbfyM biskcomp.local" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIoHW29TmS5FgK12N+bCXhGWASDdmzqSEA0QxbyGaJ+j nixquick.local" + ]; kanivanKeys = [ "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDUSkj7587e+MAUNyU/KRpw9Vk++53Wv5nB+0V1QgiTO3rMQe6HJt0Tm2wi/o/T8GNjueT2D69YgkqOIF1FQwsj2EFLObcMzeBgs5gTSglqggA2I91BIc1vvgjCDpogOMAzAQGlTxRnqrEXhqG0jJtw8KIzLr9WrvWLdTT4rHtWS8RoOBgkQ8oxbggZ4vtbMBIwoIAYGRr70KBRNCsLTPLa8yEf+DDQxq1entzxSjHXHgyeBSVVpPCrBVmhjandk+lIFInjvAiAE1ZkJHSRccL73ORmgb1crwH7xlD9NwBPmypowMi8UIRMKfL2lNehT0AQIlEAikUBLMDzPIPhnwLZ imalison@ivanm-dfinity-razer.local" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHEsLV27EteTsuVl1gLAZRCklpMFBMhakKbQ2+MkN5rm JuiceSSH" @@ -20,5 +25,6 @@ rec { alexKeys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIP2SQkJenAX67Ze99SKOVpKDD1XvAZnxQ8RLP0dL/Ej2 alexm@MALISONSERVER" ]; - allKeys = kanivanKeys ++ deanKeys ++ alexKeys; + agenixKeys = hostKeys ++ kanivanKeys; + allKeys = kanivanKeys ++ deanKeys ++ alexKeys ++ hostKeys; } diff --git a/nixos/machines/ryzen-shine.nix b/nixos/machines/ryzen-shine.nix index 67e44c65..6f3c380a 100644 --- a/nixos/machines/ryzen-shine.nix +++ b/nixos/machines/ryzen-shine.nix @@ -8,6 +8,7 @@ features.full.enable = true; # Needed for now because monitors have different refresh rates modules.xmonad.picom.vSync.enable = false; + modules.cache-server.enable = true; boot.loader.systemd-boot.configurationLimit = 5; diff --git a/nixos/secrets/cache-priv-key.pem.age b/nixos/secrets/cache-priv-key.pem.age new file mode 100644 index 0000000000000000000000000000000000000000..d8e3f38b790b4bef83b0a34f9712be53ead730ae GIT binary patch literal 2282 zcmZXUOUvvA9mb{7g9gsBxX{HYRFL#F_e_GNkV!JROzxM-1w}JSCYfY%pG+pvrB&Ru zs2klBTh7Xbt!`R%=?74uVzFq8xKU6MS0Z{4&*r?J;K%>>f1W4G(z~>d`?ri zpFvjyxO-_e4EbG}pag-?t1#=Gj#=gGCPe2Nb%&RP!X zP8)v!PBXTp(nQ0evp3(`fZXVT39B4_C1;)Jbx_SE`y}nVm3;fq_!#(Sv5EU|T5QvLO+ZrSs@|-p6rNAOw}+ zM&(jKTO^(QiL&&97IoAb|oTa0?Np)CJT;6T*VdsYvW|AfhRN0;% z(%VpX3%8i+3B2mq6iHG>Mpp=NB~rmA6gNoB!=KRlAzEdVe1lCOWgDau8WWY1+KaXukw~EGJiavw0*p6hf6FyOK1zNel;cUt z9p^HPM^ujNTt(XRrABOJ*0vR=*W5)Ys2sa2^HFL{A_HAO;0BY=)ulU^1P>ckquSNj zsVwO+)Vi3cFsL2*8o89uxkGiqurN{^HSGFzfm#8{0AUVehe(kp-7axjTn65XP}_IU z$IX&E_2CR@PLiN4jb%Ymv?{`$Z8$jariS?BrXc~zpl?Eh5A}dp;cQ`$+p`vC69S9k z5C|pnxnI~oA32IC(j_U5<%O<&^Psa@F3IaH;8P)mOIKo{C67ft|M0FVQu@P>xCXoj{Q?-znEpDsvZx#OPu`1rCg(%<@Fsz(y%f8#Rxmrj$Ls zWlS?{7}IEth87$=W9H_`Z=bYeXC6<@v^rLUN#(5-)tS~_nKU}C4bI-%whTtRXGLdz z9eM1u;1dI^IW$1T@LJ)*=$bd#-*!qNwnoiRAggX$oY8Aq6KZu2KTRv`Sh{7aj!838 zxdnU>GW1J5)dH7FZDBLI zvmHaqli0fHGO2Pdn!k?>ZjE23+Q>Gnv*g4rc0tfCpT6z?Cc)9&Z*8teW=TNICWf^&;`TQH)soO^L!uO zGl?{)4^Jy`Ey)gd7)%50rrSoJOB&0|EhVn^mj#-)vhVGV5h0Rr40r>)M>IM{*aeOw z8~6A#lPuGb@6+<{9Z+lsw@D z>6o?)XgyvXnuDh{+-~9*7{P??<*M2#OK1m_%=tbv2}}FK~r`?J<$x^%Wn2G4Xz@JomRx6=VHE*H;|EFQFlsN zy6Kim3q_4K0~F-?q5vnYq!}K_c8z_7^g?ens32P}Q8A^*j6)S(^JQ2E^Jv%_QKvKU zKa*by?y^3OhIGZP#%}8F+|`%A_IwB+U`cSklAfwVzgI=PMLJ&Mv&Y+dcem1{BIBsr zj$4|xB# zkN))Nl^?udKl;VPFTTb-_u0QYFZ}J}@BaD6T95qx&AWfRSbdj!{|m1I|9R)ZD;4&y zzyADVzx&bry^n_9eE$z`25)`Fe*J@YKKaL=fUkb!;V0hilCQk??1T4yExdjGs^tId rwGR>ESIO(ZOSkBsU;o_mg8rLteCjX%e&gAPZ_Ob0@{1on^Go%=w3zG_ literal 0 HcmV?d00001 diff --git a/nixos/secrets/cache-pub-key.pem b/nixos/secrets/cache-pub-key.pem new file mode 100644 index 00000000..474d2cda --- /dev/null +++ b/nixos/secrets/cache-pub-key.pem @@ -0,0 +1 @@ +1896Folsom.duckdns.org:U2FTjvP95qwAJo0oGpvmUChJCgi5zQoG1YisoI08Qoo= \ No newline at end of file diff --git a/nixos/secrets/gpg-keys.age b/nixos/secrets/gpg-keys.age index fcf32d1cc24e6a4af3a906d71de52f4042774742..b3a76249c63b32da4b41163e423b819c0f9e08ec 100644 GIT binary patch literal 5514 zcmZXV`Bx1H*vB(c+$@=-(BzsVTy^(Np}X(<+ATGAU%LB#Z;2AgR+GlQm8EP&sF7_% zh6*7Pi5R=Gr$XL&&w0=LgE`M1@HyYl^PKM^*Q(>yW~JR{b?PnV1dCk@c0&R2^MMYB zE?%vIA(2olP^PsDZ8#v74Kmn43~LHh2#0G-JdTX+!3c388O!NaG>kW42=<|bhNLzClG0xb}0cQO1d zh|GuvNmx3K2|?koP;|W&>o6N2IH?u}Wt*@LGTjIh0sK5=CY-|M30Pp2-Xtd=1vmu} zqY$Y;9GQg8RBF+1kxiCKQc4g%(pXfP&*%Yytxl9#BxX8YNT`4da$D2{v>DB}@)dfG z7>f4T#Uh*ztImm-BZ1x7!_Z)S_|fE2jLF1H9%EF>OPg`n{9a;U>X)$siaii``>sC|ro zM+9+Eh-P03ON+1z?J$-C#Wf3%J~J%^3vg?^L>`xbWa@NY23(2sNW~DdL(k+Zd1rK3l#?x`&4*5OU_5C*l3eNs)tIwX1_tt2O)TL49zQJL&$ap8ZI^RNC3FY zD{^9t3=yf(=N}GV? zrOSCH36r7JSh*G#h2XRQCtIdKN%LxfQl1`y;2NN4s#WfXu}w;vjBVryVVTAhxy^P@?s zUkdemfHDdiBk~f_GPjH3=Tb~yHrL~)aivNE$AC0Z&03T~&1NEyZ~_j%!fQx8w~Vc@ z(s*nN%&P?E~pGk~?K}n&AjcUA!V^Fa0KBCoV z^+NSrzgB>AW3@~(!mQL%uo@!{U_truToeU_M6$qACq?LCq&VOPHr%V@TihPMfakEF zkuC)bjQ>wIs0Aj4cz}41+v&5zT`0o8&S+$?&TQdgbaE*KMKzEuVjqv_G71GQ7@BVZ zI7B`SmP*uH7-}(y5}YE$@MS^)6^qi6GBbZP2~i7>ARJIebmDzBs#8a0BO!d1RGNu^Lt$Dw4vl1( z2~wXFWWvLA4wJ{g0tm%?6WFKH(G6A_0!8<0U3e0RN=GY@1d9*k1!LT1nVCh_>JiEx zX;?6VYxe++6tYckweeI&mWLsAVa-I3M~{$^+z1l{Yn2<^Oq$WDmEwtd3_!)Am}nM^ z*a9=^9Bj1S<}xCMP%+QU(_+LJH537th*@s0jxKWiNYmmn;UFFmuORCQY?;E%Cqk)i zJlCr+yN`e*5fx0*xH^gnjS=oM!R10FNsA7v7 z$rf2047UKSrb+($C!{Df#mNKOnZgtqk?SF9`5Lm+;57@tG9etS#>vzw0#)PFQnYF; zNp17-lmH`5!l$z-Y$1jq$4i++23=`zs>vWI(IHULWH5+YLZjjZ8U=>-V>XCMjv;t} z7`I)5bee?pe_Ph!N23jF69W!|@C-_VkD!v^@gkfDXNJ<5J_i77Gx!ApjmxW-Tbxj# zM2&`uKsXrRK!U;yaETeBLyIABnO%)e`Cl5!Yme93)pCa#07X++BC`-rVme7evPUgY zpmcnvT%}9R9yLDFu;_ROdlHhhQxcbOzvl*O!d!ORQL|1c7 z^G^SUAr+mwZg|J)$IqC9W8<5E1j>h~p%CeYCycG7?oiD}qBiBR0J)xjblG z?GwMBClMAmtJBvC0+(+e?YtM5d^g^?II3px`Qu@OXD$r$b@XN|ostuzQ?{2~oLd~7 zO{toCx#IfHJEa*zrtKl0G;^M3f6ij9`4W!LX{ZW9e7eLd$&9;qHtA())5_%gkGSjB z*K7A%o{OHftoLpym@{eXzSM#v8U5*ynDx|*N2piiw7Ns(9m)H+`}?==+V^zq5zDNB zs6Sf|Vs$rL*c-XKPTD9XS?&!LlO6UF@ycs)kDh%WDqcM!05>^*>W(ygR#?FH(;gXyuzdJW~x$l%sk`09X z;+9|k<8;lptvl%-qr!h~_^P_-i0l3!bUmZ-&CHG z@H$cNjHkn+9+WP3OLkX{t!Sk zDxK?iXnRn9<`{MAsPyWu6Fzp1i2uWqw;nqFPTqUcpBWD@BTuw-@0-cK^f>5Z#hv4< zV(U*GcR`y=&NUnqbgx*wb9v*=q^N?eNvKdSwmVDrqQ=jAG@<4yzHRauFf>OR+_QD{ z$am`EVO`(kegAyf-n3izP2@Ni%XW>^ubA+OOOyT5J^n6a?cwQ(z_oM6=gxfsY@_?a z8lFVAHDC`$Cv5pGv_JP@*jHR|+mT7r6P90^C4Uy2_jD%@k^J+f9`OviW#HKG3AavPSTuE1#>i0<^A1l-=!HIv>^fODNGO$721iy0l5Q{V zz2@?b%M+(1#Gb$&>#2*sw}H+RuW1b&KdHzJZ3qeezSUTxTeO#qT~qtMtT8#(h?=^3 z$!{(mV?6e5OVbVSJ3iH&ux$w+%dz|Gy7YoEx~U*K*UAP3u-#ipVXFNs!wQ(y*;aDcL89DrU6_s>m=*>#@H>-N=8Z;^50>UUG~m)ISv zlD`t~<`&+r`%G?pDtx4iYoGj^^6!tDgecus(*&}oJu;Mb|Upuj9&0I zDU#1)%&k^GIuyT`DO`Jq-`z_@Oa^zX_&)ZtWj*$u5mWB^?`31xf4u^p>g z$sqF~`Y+!Ob3*DjJ&3>!MJ+$SxAN51aWP%PVRN)O+~=2`$=iRQ^zmr^x-wXLUB%tH zl9YlKkI5!qoWHnp4o5d4H~9&JMR>fEIV@~c@%CkV_csOR-uSCJc-vjz4(X^k%;%~u zstE3=SX*1rcW9Fl9u;avqsW!G-Jlqs??X~-|WA9VX5_YA+GscMQZn( zV!^iuzimR5r4U*q-P1KYI*gCb-jWRS-GBaiyYT~N@y-PkR(2%Znb~{-*AgR7i2n1- zI>~HzDD^{B#l6#L+TNnJ&JACm2dH@DTLA;N526qEOiVcPZDrlB6Yh5n=+RVWIqS&D z@Y(_WhaS%5W6{^rTGM8CS$9mFzb${u=9s`w!Q-x5QPf+Eu1wGkMSEZ=NhdfvqY3QLvBU@&vu3U}Zam2T* zw`w5q!Kl=-fnSUNO4S_eurZ#0wqSQxQ0UX*jzhCR?;HLJmAzsIwRB#IdH?lz&&N~X zb3v1oVg4EWS59mG(6ZY)R>mLuEJu_Tvab4I(dlQgduAlZdF|5=WMqpQ7r&yu-4zWA zYbMwW;q!p8V;T1Q0|T+t%Yfa>ZYm1+R6m6^fo_0qq1TL~p=?^m&yxVXT-FtIqK-GP4 zCor`CdW5yJ&-%2e%X6;rb(6$Zxu#BY>sBWg)Q6*o$T~mW7_+fcNABB1t-haS=f3>& zW!rs|FD87j%L*pIpYY4!75$$tz8e^dk6nTM#8mEx%G)yY`k}>sR`l$javJ&~OWIXU z9Bfh4#1&lo5?G5bCUdI#(UGuw_M5pG+oYkX)`DyNeIL)BA?)K0lT*&B07J;JRnyWM zZuRUce|7u2{&be%aiHa!yl}$c$?BGksh6XVdZ8^{qbJ|#BZT8uM9kXhZ`$~Lbl%Ry zqZj8-ew+i|fZya>dWG3qQkzhb)OYFDp5xqiGcCK9{6qO-eLe2hEXrz*&I8Ige-#zQ zdbeOl`0Ua^9h=UR(b_N3c<;A1uThc~m(~n6!d`S)E`GXyXB4XR7vh>V#Rm+{-b^R+ z$f=-^Pm_vCE`_v65Z)p^vKp zF5Wlx?^W}U?(6Gcbt}EMmU^L?e-|X_^9Cif?k2z7F@NSX5cYPc%=L9qUsl_u&+ALS z`%cy4rTh!Wud_`a$=p{579L}!q8GbC8^nUBzDlAA$+l(HC=r<6j;yiiW?dhg2Q}KU3n6qH?B$>Lkw@S?*)c$ zdosq_F=xd2(!Hgwye&J7kKz++>Jyb&b#-I1Z6(vQdzbxj(syB3W?T8I#b>@=Zaxsy z5y4*GDE36pRDIuufSzd4ohO|u=pMB@q^k8yNq2Im`5fsT&J&3CT4~r2F3f#4F}0E%{BW^t0EWIkhebJG*q|m}1qi z({G&3Ez8zVYPg>seyECG`T)MYusPzfDSXTuP|Uhi?S>iax}Ikw{Tk)Efr?nVE-3fx z>(|eE1DZgarJK+6|720QwM#R{U%{s(Mfb#{U6n@jv7<%v3Zzq)z8=%L(p_8m7EY@h5hTx^P$onS9n! zpNEPuzpWnH^Hh}h^Zns-$e_EEsiXP?!yXcTPigq|3P|72YW2}x482|wwwYYql=u4d zLZC!pnzQEyaU)$+AxdBDEm}B#GNX*c?0yoy?Afb%`-2rSW!HrIz=XkoEl)vvNuokZ zmL&3X-;{T4xp?f~>FbR~?af}nDO=m}xfiHc0>d6up9woQzc|S8CNyf^LD|@~?BvaV z?!GNi%JXkBn>(ut^;lF+LtvHRa<5YZU$(h&aN!2bY1|ys&=y)(!Jjws(!&z7qLk;b zI5GNe#L=M}59c*}&&3|7F-{&yI6rrN>aiC9++Gwl{}4HOka=MYs5Sx89E&~Lz++?g a%4-VOAEE?S8dkXr+{r literal 5255 zcmZvb`CAMM!@o&crmUr7E7Oiqvu}iEnx&a$-)AJ6eV=LenMfra*`TOP0A`FoT!z1GbL;%DfV!0>;Q@mZM)w5A%1lFRE(S=BZNot~+5qfbd#Rj)H ztrCw;s!~$eFp`WLPbN^sP>Bi5AQ%ArM4SyrVz6;K8XN?77|krGT#bWj?PLka%2l$d z930MyBC|~<6q3bDfzZG@L!yjl%t*$Mh?njR=A{Mi3NdnkQpu#%c`(@kOmeLX@z2#WPnUV5(%6LHIgG$G35|EhAQHi z!6b$mgBK=PonSqUl7c0g^h~J~#-ONDnGTN%qE*omESZRsh{pp=5)z3dF=@39CP62H z8SNw!S)}^k+6p-giG*T-ViLuafCCb(BoP^Iaj0FSRwklaq9&TYoRC2*!7g`6remZ`qLA{~9;3#LbLkuuB~Hi?LJ435SZ9+G`2a4|q-Sx#NJ|2i zW(K9;3>Jr0rAASNQU=%#gG)&^5}I$YBx0=ef75ha8O5anq7`m(s+r6rm^d`K&@R@y z6e&!U91B(n`BVp-1A}m=8k2ypBq9KI93hpjVUURe5ex}4^Y|ilyh})vVufUw5$r)3 z$xxWqAWIav{;OnyM+EgafiMjc<%WUv4zY=*AWJbK1rZG~DDiG5hsmT!2#iE1Ly;gb z!U#kF0Sz}%aZm%vWks3e6O?YWH6F>Lb1`Uvlx#3lutu|iC3HbKV*bC~{(nh>g+~%` zg+ex7BU2M-7P?-mrKK7?FtD4bN6Lg0G(%vKYG^Kq7$9_rv}^*}!W2ST3W^9yHy4reR4C;^&Bu*xNDS|Snz zrSLFF57y$+>DU$(1b~sj2vk>s5=s;qKwLi6MEuXLIz10Vq$Ge;P=r;bP7%5^CcW_g za6@YNIAAJ8B!uy#Vg!Wl)Mf({W%`5c1^fV1)v{__PY zKhc4pY87k&!=l!6@dP$Oz(VU~G^hy1M93g~3rzR#k`M(K3Bmz&NU%l$k*jG|ty~rl zC7_WB4x0gDVuN@rng}bxm=O$KJVXM95&=jvf|Ur@%JmM3#q6<=Xk>Ie-$*0UNJ=Pz zZgml03M~sIR~x9rf77sF1k2(Cia=TlNdkrQWE7Q72bT+Y3>!y51(C%GB!~v5M!}E* z4U8g2lAQn$PEAF~;A9?}NHqx69)t;FQ{b!?ib=t9)A@83%q}oUkYt=q{BN2Hr-Oso zKn=!eq%l=sg@9&5!;mID#K9*JFme*aWuYVNJOmz2BWQ35c%BTPL}1Az6OE{#A%tA3 z9?Ic*xF`l!oN+hLPG+LBE z2LO@qNUB8YBARp@I|q)Du|+bOnnouZU`B;b#^WMT@m8de;*|eCH+WhU$r-J(C{nBn zAbSZgi4II%0LKF9u=!Ls8(^eDU{rxxiKjSqN(K>$gUeIQo_IRSfRrLod>7Gf65?@g z1QB9o8HE;>+yNIGEm{uGjiNi`Pz?Ygu!#s{7cNDPz{*JK6cU)_LPMZr8Qh^w#K*@w z{`14=Xdr~o5cBXTcY+irr;|-AqF$n8+f=dyoB&3Kr^*FVBZi@~OAH(_pgSY0HKp_E zZN!|It0%@LX5f>=i{`f}oXsg?+mrYIey$;6f@@1LWj_aJtZVsM+0fLm^vB@`Z(j=M zg|xj6c;6E~rXldcWO$l(h>`VVsUV~W`M&qv%lz=Qt_`c#&Q8$XteU5& zJwrXexorJ3a4jrxa_Hzw%3FP{1#0e~7U^mqs2lTvJ#QnA!-XtPnCm&=xVlpmfSEJz za^!{p(Z3 zsOd+*GhZ%!d#0|16CAs@ZD-|aW)u0)&U-(eR|F+RGu3NgAxhvtLXzv+yqx`+M|0h! z5npdtZL{tNwxZ9KH zXch%}W8LkQXWqV)53SrDR=l$Bef)DiHSLrkdTnTQ-NES4(BrEa&%%h%`D)iCL1p}| z2`6&j?pf87ll>W*OuFc!AM4(DbK_uGyX%PWAK{zRS;K*4?uY72=h;un19soFF`nGk zbsP#jTs<{?!iZnUw8>-g=U-#o>AkZl>=hWF|s`@WLkM!YQN7OEe3f`Ng6bLk{22ZR8^@te z6gQk;?QYySYTnh?XL768u+fT z`Su$t=Eq{Mx}z4YjQSfj;@_@Z^@BGZ`|ZrY%QfA@$)2h@+MzqUUVTch;eGszn`KjN z&Hxvzd3mIJr*9;lVBNR&gm>~k8_E7Rp)ICGU!V)VWPD8$-}*kwbU5+C%Sn!DQI~%% zzWSt{oKf-Y)~ARp;IAS5ytBMa{DPw$tLc}zjU1_v-+$>^+WEyFe(IO`y+DdhlFs%+ z^q^0b>sBqVFLA8@r?TlIJv3=+DHMO|U`WF&Q{QO+)#)YhJ70V<`j5fvF#Sv86zD7Nwo%6oN zzF*#WV14+XFTA_Uxj%?GS-^h4j32|cA04BTn)hVpeh)qaj!jN_ydp5VaN8r^u}3!( zo__(D*48f>+eaT>Ui`!QxP)BYkvVbP*-3ri zuqA|m?cwt~KD_!|S|JXI&ihss92mB>w(icPfC-Fc->91S@!>65Sn?=~AD123>^Bcl zQ(?K7Mv4f|UHm#1rdq$L_V%v!MSqC%h&Ns#Is(GC86Pg%208ZP;W$XpfzBNtuXr`0 zfqlnrnKFdk`v#B2G>{s9d~=@rFu}}8pKet)?cE9S2b^)p8-I4spXn2~us`rJRl<3Z zuxV+BGw%zo4(}J)RrqIES)30MC0;WN zs;;!RZjcuC%?_xWdwNuZfzAY0>@#UrMTb*2LC~`r``Re;oSFQJUA|h_|{(#3#-`{OImg{z;wM>ED(I>s%Ci9IS8+W&MEUC1?e@EBO-KUim zQF|-jJ349JJ8CZ+rtGinNLxjezdj6jSx~9yp8tU2tVp2%uH=-}cm7jst`9_!|zV!Hz-zk5-4=1^)(aVh0Iyynl-`v`ZAS6y!+ zryOs;Z~wXFzIP_MV#t6gl&iijUAQ0sb>t}SO_KQ7#~pulu2q)wIBTfDzDHNx2UFkO)sxGaij9?psR;J zQ1W)&;J}zDBC;iuXxq7L-P|$w#V06*#{`r3B2RJDrZvA>FJ_efZC94RAss%8sQtKN z?oi&v^;w>SBA{L{*BOggmuD@%D)O9Juq4&5cdGY24dK-%zw-`8ptvd25WEVc znY5|Bb#qqwMEH!|bMiIizsM`kdMvFYt0Q4uGt}MlWZw;Ua?i{xw+oGBo1bwP_DtZZ zis8{k&0lf{a@K7q@%9?TjL9pgpB?x94XesKD*DRc!MnxZ8ylT{H$QbiWXpeconDmy zO+A{(3D0Faw&-p1BhcU<~*IY#p8{Kj6R_uGs~nWbU^Y&B$g-d%Wc zcYFQ8IjH24Dc2|Z3vyF^f2$gq__;qEu>W(j>>>SQin@hVcL30y49i?@K3ennTg1CK zZybdDF@x~l#wBDAnXt&3Thnw2m zVSu9jRB~rxrxLE~**LhuyMG~hh9GWc<-j_G;q3X6Q%7%juQiVfS|ipC7Zlc4hjA+> z{hbR4Ss!w6ynFQucJscarZ~u`nWux;rH017?HT*iEGkvU*v7kt&L->xFHo^hf!)6K zR(a5>tr3r-mn;PLpBR~%VJ$qGp0^ex12U>&g5q}9R6oxhS-6y8-4-$lk|=E`xm**| zT|DI$Gp1M8r4`l*>WcCUftP-}2ar;X<6|+~6y#gX%mR-Nu@6xZ%qDbY%a#!LD8NyW?2-+2jmdTd^dl5--gzSl6Y5Eo=!ZiSyrk&fBtn z>PFb;Y_C(6+sBr?NUyvcG-M5?ra-Kd6j{Eg$2zjb{~LDT{7lkZUz-`r&0Rh+bMe$` zmy0+F&76v9ja?7xN^%#z9F2z5uL^E?x3UD896&65Hq|uPJG#rKXu`W;+K=Ej?E>G& zXJ0;TY#9ByF@Dpg7to0CU)v}(UmmZom=${qTj5)Da<4|U4>D%s;)Bzx za2@yPm+jVV?-RqWf6PnIETo4zf}1R>YGE&A7~>_{Ut2;^QxI2`sPLE*PVS@s0hRFC Ab^rhX diff --git a/nixos/secrets/secrets.nix b/nixos/secrets/secrets.nix index fc7386c0..e4a449e0 100644 --- a/nixos/secrets/secrets.nix +++ b/nixos/secrets/secrets.nix @@ -1,5 +1,6 @@ let keys = (import ../keys.nix); in { - "gpg-keys.age".publicKeys = keys.kanivanKeys; + "gpg-keys.age".publicKeys = keys.agenixKeys; + "cache-priv-key.pem.age".publicKeys = keys.agenixKeys; }