nixcfg/host-secrets.nix
2025-06-11 01:13:48 -04:00

35 lines
731 B
Nix
Executable file

{
users.users.garage = {
isSystemUser = true;
group = "garage";
home = "/var/lib/garage";
description = "Garage service user";
};
users.groups.garage = {};
age.secrets = {
"build-token".file = ./secrets/build-token.age;
"garage-rpc-secret" = {
file = ./secrets/garage-rpc-secret.age;
owner = "garage";
group = "garage";
mode = "0400";
};
"garage-admin-token" = {
file = ./secrets/garage-admin-token.age;
owner = "garage";
group = "garage";
mode = "0400";
};
"garage-metrics-token" = {
file = ./secrets/garage-metrics-token.age;
owner = "garage";
group = "garage";
mode = "0400";
};
};
}