mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-10 05:55:24 +03:00
sops secrets path changed
This commit is contained in:
@@ -92,7 +92,15 @@ in
|
||||
# is the only source — and the container will refuse to start with
|
||||
# WEBUI_SECRET_KEY="" (env.py:762 — SystemExit). The error message is
|
||||
# the clear signal that the secret needs to be created.
|
||||
environmentFiles = lib.optional (builtins.pathExists ./secrets/open-webui.env) "/run/secrets/open-webui-env";
|
||||
# Path comes from the sops block below (`config.sops.secrets.<attr>.path`)
|
||||
# rather than a hardcoded "/run/secrets/<attr>" — see invariant S1
|
||||
# in docs/arch/invariants.md. Guards the sopsFile existence so the
|
||||
# block is optional; the same predicate is what `sops.secrets` uses
|
||||
# to decide whether to declare the attr at all, so `.path` is only
|
||||
# read when the secret actually exists.
|
||||
environmentFiles =
|
||||
lib.optional (builtins.pathExists ./secrets/open-webui.env)
|
||||
config.sops.secrets."open-webui-env".path;
|
||||
volumes = [
|
||||
"${panel}/data:/app/backend/data:rw"
|
||||
];
|
||||
|
||||
@@ -6,6 +6,15 @@
|
||||
xlib,
|
||||
...
|
||||
}:
|
||||
let
|
||||
# Composite env file path shared by the generator
|
||||
# (remnawave-env.service below) and the container's `environmentFiles`.
|
||||
# Lifting to a single binding prevents the two copies from drifting
|
||||
# apart in future edits — see invariant S1 in docs/arch/invariants.md.
|
||||
# Note: this is NOT a sops materialization (it's written by a oneshot),
|
||||
# so `config.sops.secrets.<...>.path` is not the right primitive here.
|
||||
envFile = "/run/secrets/remnawave-env";
|
||||
in
|
||||
{
|
||||
# Runtime
|
||||
virtualisation.podman = {
|
||||
@@ -58,7 +67,7 @@
|
||||
# "WEBHOOK_URL" = "https://your-webhook-url.com/endpoint";
|
||||
};
|
||||
environmentFiles = [
|
||||
"/run/secrets/remnawave-env"
|
||||
envFile
|
||||
];
|
||||
ports = [
|
||||
"3003:3003/tcp"
|
||||
@@ -126,14 +135,14 @@
|
||||
User = "root";
|
||||
};
|
||||
script = ''
|
||||
cat > /run/secrets/remnawave-env <<EOF
|
||||
cat > ${envFile} <<EOF
|
||||
DATABASE_URL=$(cat ${config.sops.secrets.DATABASE_URL.path})
|
||||
DATABASE_PASSWORD=$(cat ${config.sops.secrets.DATABASE_PASSWORD.path})
|
||||
JWT_AUTH_SECRET=$(cat ${config.sops.secrets.JWT_AUTH_SECRET.path})
|
||||
JWT_API_TOKENS_SECRET=$(cat ${config.sops.secrets.JWT_API_TOKENS_SECRET.path})
|
||||
WEBHOOK_SECRET_HEADER=$(cat ${config.sops.secrets.WEBHOOK_SECRET_HEADER.path})
|
||||
EOF
|
||||
chmod 600 /run/secrets/remnawave-env
|
||||
chmod 600 ${envFile}
|
||||
'';
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
};
|
||||
|
||||
@@ -58,7 +58,9 @@ in
|
||||
"NOTIFY_DAYS_BEFORE" = "7";
|
||||
"TZ" = "Europe/Moscow";
|
||||
};
|
||||
environmentFiles = [ "/run/secrets/tape-rotation-env" ];
|
||||
# Path resolved from the sops block at the bottom of this file —
|
||||
# see invariant S1 in docs/arch/invariants.md.
|
||||
environmentFiles = [ config.sops.secrets."tape-rotation-env".path ];
|
||||
volumes = [
|
||||
"${panel}/db:/data:rw"
|
||||
"${panel}/uploads:/app/uploads:rw"
|
||||
|
||||
@@ -44,11 +44,6 @@
|
||||
let
|
||||
cfg = config.host.authelia;
|
||||
sopsReady = builtins.pathExists ./secrets/authelia.yaml;
|
||||
# sops-nix materialises each `sops.secrets.<attr-name>` at
|
||||
# /run/secrets/<attr-name> by default. Hardcoding the path here keeps
|
||||
# the module independent of how the secret attr is named; rename only
|
||||
# the sops block below if a different path is needed.
|
||||
sopsPath = name: "/run/secrets/${name}";
|
||||
in
|
||||
{
|
||||
options.host.authelia = {
|
||||
@@ -105,8 +100,12 @@ in
|
||||
package = pkgs.authelia;
|
||||
|
||||
secrets = lib.mkIf sopsReady {
|
||||
jwtSecretFile = sopsPath "authelia-jwt-secret";
|
||||
storageEncryptionKeyFile = sopsPath "authelia-storage-encryption-key";
|
||||
# Read paths through `config.sops.secrets.<attr>.path` (not via a
|
||||
# hardcoded "/run/secrets/<attr>") so that any future `path =`
|
||||
# override on the sops block below is picked up automatically —
|
||||
# see invariant S1 in docs/arch/invariants.md.
|
||||
jwtSecretFile = config.sops.secrets."authelia-jwt-secret".path;
|
||||
storageEncryptionKeyFile = config.sops.secrets."authelia-storage-encryption-key".path;
|
||||
};
|
||||
|
||||
settings = {
|
||||
|
||||
Reference in New Issue
Block a user