xlib+users: centralize opencode server.env path

The path '/home/<user>/.config/opencode/server.env' was duplicated
between users.nix (sops materialization) and home/modules/opencode.nix
(programs.opencode.web.environmentFile). Drift between the two was a
silent auth-bypass vector: if one moved, the systemd unit would either
fail to find OPENCODE_SERVER_PASSWORD or skip EnvironmentFile entirely.

Single source in lib/xlib/dirs.nix; both call sites now read from it.
This commit is contained in:
2026-10-07 11:36:55 +03:00
parent 534fa429e1
commit b2718fd1e7
2 changed files with 5 additions and 1 deletions
+1
View File
@@ -14,6 +14,7 @@ in
server-home server-home
services-mnt-folder services-mnt-folder
; ;
opencode-server-env = "${user-home}/.config/opencode/server.env";
user-storage = "${user-home}/Storage"; user-storage = "${user-home}/Storage";
wsl-storage = "${wsl-home}/Storage"; wsl-storage = "${wsl-home}/Storage";
+4 -1
View File
@@ -111,8 +111,11 @@ in
# Decrypted as a single dotenv file (no `key`) and consumed by the # Decrypted as a single dotenv file (no `key`) and consumed by the
# systemd user unit opencode-web as EnvironmentFile. # systemd user unit opencode-web as EnvironmentFile.
# Source: secrets/opencode.env (encrypted, see sops/age below). # Source: secrets/opencode.env (encrypted, see sops/age below).
# Path is shared with home/modules/opencode.nix via xlib.dirs so the
# sops materialization and the systemd EnvironmentFile can never
# silently desync.
opencode_server = mkUserSecret { opencode_server = mkUserSecret {
path = "${xlib.dirs.user-home}/.config/opencode/server.env"; path = xlib.dirs.opencode-server-env;
mode = "0600"; mode = "0600";
format = "dotenv"; format = "dotenv";
sopsFile = ../secrets/opencode.env; sopsFile = ../secrets/opencode.env;