|
|
||
|---|---|---|
| .. | ||
| omni.yaml.example | ||
| README.md | ||
omni secrets (sops-nix)
Encrypted YAML files in this directory are decrypted at NixOS
activation time and exposed under /run/secrets/<name> for the
services that declare sops.secrets.<name> to consume.
Recipients are declared in ../.sops.yaml. On omni/bohm the
matching private key lives at ~/.config/sops/age/keys.txt.
Workflow
# First-time: create + encrypt the omni default file
sops secrets/omni.yaml
# adds the sops: metadata block and encrypts in place
# Later edits go through sops (auto-decrypts, re-encrypts on save)
sops secrets/omni.yaml
First migration targets
See ../modules/mcp.nix for the current plaintext-file references
that should move under sops:
forgejo-token— Forgejo personal access token (forgejo-mcp)lnbits-admin-key— LNbits admin API key (lnbits-mcp)
Once secrets/omni.yaml exists and is encrypted, declare each in
the consuming module:
sops.secrets.forgejo-token = { mode = "0400"; owner = config.omni.user; };
and switch the path reference (e.g. forgejoTokenFile) to
config.sops.secrets.forgejo-token.path.