use ssh host key as identityfile on tempest

reencrypt secrets and use personal key for mail
This commit is contained in:
Noah Masur
2023-08-05 20:06:03 -04:00
parent 5bc10bef87
commit c845ae2fd4
23 changed files with 239 additions and 203 deletions

View File

@ -104,7 +104,7 @@
# Used to login and send and receive emails
passwordCommand =
"${pkgs.age}/bin/age --decrypt --identity ${config.identityFile} ${
"${pkgs.age}/bin/age --decrypt --identity ~/.ssh/id_ed25519 ${
pkgs.writeText "mailpass.age"
(builtins.readFile ../../../private/mailpass.age)
}";

View File

@ -38,7 +38,7 @@
};
# Create private key file for wireguard
secrets.wireguard = {
secrets.wireguard = lib.mkIf config.wireguard.enable {
source = ../../../private/wireguard.age;
dest = "${config.secretsDirectory}/wireguard";
};