rekeying secrets

This commit is contained in:
Anish Lakhwara
2023-01-10 21:05:23 +10:00
parent 0897332293
commit a346131bb5
8 changed files with 52 additions and 47 deletions
+3 -3
View File
@@ -1,18 +1,18 @@
let
# set ssh public keys here for your system and user
user = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIItTdCyYVur6LzRQf08JZUcEAr23H7fTRRmDJOzoOc6A anish@curve";
system = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIMPcqWQ/L5nLTsBFHArl3AJb9xynhfsKenb5h0NNuMV root@curve";
system = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIE4kI2giQrA/VgM/Ao4T+f7npcJ//acKZ5yY+eUuVzbB root@curve";
mossnet = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAA0bsVbdQR6iWNLKIiID57A1+dVXC58Dtf5cSXg6/JF root@box";
lituus = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIH2lAb33LH3JNuOfBXt971u0tHe+NURFecQdfjwEj+C+ root@lituus";
helix = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAKrL6IDHNnHmxi0q9nzu87NOyidPm3HpE7klU368lEf root@helix";
curve = [ system user ];
allUserKeys = [ system user mossnet ];
systemOnly = [ system mossnet ]; # lituus
systemOnly = [ system mossnet lituus helix ];
in
{
"fastmail.age".publicKeys = allUserKeys;
"mossnet.age".publicKeys = allUserKeys;
"curve-wg.age".publicKeys = curve;
# "curve-wg.age".publicKeys = curve;
"box-wg.age".publicKeys = [ mossnet ];
"wallabag-password.age".publicKeys = [ mossnet ];
"wallabag-secret.age".publicKeys = [ mossnet ];