alpha
Login
or
Join now
robocallie.pds2.on-her.compute…
/
nix
Star
0
Fork
0
Atom
Configure Feed
Issues
Pull Requests
Commits
Tags
Feed URL
Select the types of activity you want to include in your feed.
This repository has no description
Star
0
Fork
0
Atom
Configure Feed
Issues
Pull Requests
Commits
Tags
Feed URL
Select the types of activity you want to include in your feed.
Overview
Issues
Pulls
Pipelines
nix
/
secrets
/
at
main
1 folder
45 files
Callie Peden
init open webui
15d ago
0da5dd85
publicKeys
nix: distribute per-host binary-cache-signing pubkeys Adds public halves of Ed25519 signing keys for madoka, homura, megatron, and reef, plus a module (modules/nix/signing.nix) that trusts all of them on every host via nix.settings.trusted-public-keys. No host is a signer yet — myNixOS.nix.signing.enable defaults to false. Once every target has picked up this commit, the encrypted signing secrets and per-host enable flips can land, and unprivileged nix-copy-closure will start working without a trusted-users bump.
1 month ago
atlogin.age
atlogin conf
4 months ago
authelia-jwt.age
reencrypt
1 month ago
authelia-session.age
reencrypt
1 month ago
authelia-storagekey.age
reencrypt
1 month ago
authelia-users.yml.age
reencrypt
1 month ago
authentik.env.age
reencrypt
1 month ago
autobrr-session.age
reencrypt
1 month ago
bridge-keys.json.age
init open webui
2 weeks ago
bridget-client-key.age
reencrypt
2 weeks ago
cloudflare-dns.age
reencrypt
1 month ago
comail-sasl.age
reencrypt
1 month ago
coral-secrets.toml.age
remove old opts
2 weeks ago
coral-webhook-token.age
reencrypt
1 month ago
coral.env.age
secrets: fix coral_reef_pq pubkey to match user identity - coral_reef_pq.pub was a copy of reef_pq.pub (root identity), should be the coral user's actual pubkey from ~/.age/identity - re-encrypted all affected secrets with corrected keys - coral-secrets.toml.age: now encrypted for both user and root (root needed for container activation) - coral.env.age: changed from coral_reef_pq to reef_pq so user can't decrypt (matches the 'she can't get this one' comment - has real API keys) - slskd.env.age: encrypted for user identity (root not needed, runs on homura) - coral-webhook-token.age: already had both reef_pq and coral_reef_pq - updated secrets.nix to reflect correct recipient lists
1 month ago
dex-jellyfin.age
dex pre-build
4 months ago
dex-oauth2-proxy.age
oauth2-proxy
4 months ago
dex.age
dex pre-build
4 months ago
garage-admin-token.age
add keys
1 month ago
garage-metrics-token.age
add keys
1 month ago
garage-rpc-secret.age
add keys
1 month ago
gluetun.age
add keys
1 month ago
grafana-secret-key.age
add keys
1 month ago
happy.env.age
add keys
1 month ago
home-assistant-secrets.age
add keys
1 month ago
letta-password.age
add keys
1 month ago
llama-api-key.age
add keys
1 month ago
mail-passwd-callie.age
add keys
1 month ago
minio.age
add keys
1 month ago
muliphein-pskey.age
add keys
1 month ago
muliphein.age
add keys
1 month ago
nix-remote-builder-key.age
add keys
1 month ago
nix-signing-homura.age
nix: enable per-host store signing on madoka/homura/megatron/reef Ships each host's encrypted signing secret (agenix, encrypted only for that host's root pq identity + matching callie_*_pq where available) and flips myNixOS.nix.signing.enable on for the four hosts that have pq-based agenix identities. Once activated, each signer stamps its locally-built paths with its own Ed25519 key; every other host already trusts those pubkeys as of the previous commit, so unprivileged nix-copy-closure works without adding anyone to nix.settings.trusted-users.
1 month ago
nix-signing-madoka.age
nix: enable per-host store signing on madoka/homura/megatron/reef Ships each host's encrypted signing secret (agenix, encrypted only for that host's root pq identity + matching callie_*_pq where available) and flips myNixOS.nix.signing.enable on for the four hosts that have pq-based agenix identities. Once activated, each signer stamps its locally-built paths with its own Ed25519 key; every other host already trusts those pubkeys as of the previous commit, so unprivileged nix-copy-closure works without adding anyone to nix.settings.trusted-users.
1 month ago
nix-signing-megatron.age
nix: enable per-host store signing on madoka/homura/megatron/reef Ships each host's encrypted signing secret (agenix, encrypted only for that host's root pq identity + matching callie_*_pq where available) and flips myNixOS.nix.signing.enable on for the four hosts that have pq-based agenix identities. Once activated, each signer stamps its locally-built paths with its own Ed25519 key; every other host already trusts those pubkeys as of the previous commit, so unprivileged nix-copy-closure works without adding anyone to nix.settings.trusted-users.
1 month ago
nix-signing-reef.age
nix: enable per-host store signing on madoka/homura/megatron/reef Ships each host's encrypted signing secret (agenix, encrypted only for that host's root pq identity + matching callie_*_pq where available) and flips myNixOS.nix.signing.enable on for the four hosts that have pq-based agenix identities. Once activated, each signer stamps its locally-built paths with its own Ed25519 key; every other host already trusts those pubkeys as of the previous commit, so unprivileged nix-copy-closure works without adding anyone to nix.settings.trusted-users.
1 month ago
oauth2-proxy.age
fuuuuuuuck
4 months ago
open-webui.env.age
init open webui
2 weeks ago
pds.env.age
add keys
1 month ago
piclaw-keychain-key.env.age
add keys
1 month ago
porkbun-dns.age
done w computers.sex
1 month ago
secrets.nix
init open webui
2 weeks ago
slskd.env.age
secrets: fix coral_reef_pq pubkey to match user identity - coral_reef_pq.pub was a copy of reef_pq.pub (root identity), should be the coral user's actual pubkey from ~/.age/identity - re-encrypted all affected secrets with corrected keys - coral-secrets.toml.age: now encrypted for both user and root (root needed for container activation) - coral.env.age: changed from coral_reef_pq to reef_pq so user can't decrypt (matches the 'she can't get this one' comment - has real API keys) - slskd.env.age: encrypted for user identity (root not needed, runs on homura) - coral-webhook-token.age: already had both reef_pq and coral_reef_pq - updated secrets.nix to reflect correct recipient lists
1 month ago
slugtan.env.age
rekey
2 months ago
umans-api-key.age
move bridge to homura
2 weeks ago
webhook.age
add keys
1 month ago