forked from fi/nix-infra
Migrate mail-1 to sops-nix
This commit is contained in:
parent
d845904ecd
commit
e35aa9aabd
4 changed files with 130 additions and 122 deletions
|
|
@ -51,11 +51,11 @@
|
|||
Name = "wg0";
|
||||
};
|
||||
wireguardConfig = {
|
||||
PrivateKeyFile = "/secrets/wireguard-mail-1-wg0-privatekey.secret";
|
||||
PrivateKeyFile = "/run/secrets/wireguard-mail-1-wg0-privatekey";
|
||||
};
|
||||
wireguardPeers = [{
|
||||
PublicKey = "ik480irMZtGBs1AFpf1KGzDBekjdziD3ck7XK8r1WXQ=";
|
||||
PresharedKeyFile = "/secrets/wireguard-valkyrie-mail-1-mail-1-psk.secret";
|
||||
PresharedKeyFile = "/run/secrets/wireguard-valkyrie-mail-1-mail-1-psk";
|
||||
Endpoint = "212.53.203.19:51822";
|
||||
AllowedIPs = [ "0.0.0.0/0" ];
|
||||
PersistentKeepalive = 25;
|
||||
|
|
@ -77,5 +77,18 @@
|
|||
wireguard-tools
|
||||
];
|
||||
|
||||
sops.secrets."wireguard-valkyrie-mail-1-mail-1-psk" = {
|
||||
mode = "0440";
|
||||
owner = "root";
|
||||
group = "root";
|
||||
restartUnits = [ "wireguard-wg0.service" ];
|
||||
};
|
||||
sops.secrets."wireguard-mail-1-wg0-privatekey" = {
|
||||
mode = "0440";
|
||||
owner = "root";
|
||||
group = "root";
|
||||
restartUnits = [ "wireguard-wg0.service" ];
|
||||
};
|
||||
|
||||
system.stateVersion = "23.05";
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue