Files
nixy/hosts/work/secrets/default.nix
T
kptltd00m fe508d9cd8 Migrate Hyprland to Lua config, drop dead flake inputs, general cleanup
Hyprland
- Switch wayland.windowManager.hyprland to configType = "lua" (Hyprland 0.56)
- Convert settings, env, monitors, window rules, gesture, animations
  (hl.curve/hl.animation) and all keybinds to hl.* calls
- Add home/system/hyprland/lib.nix with exec/bind/execOnce helpers;
  every exec-once now runs from a hyprland.start hook
- Drop hard-coded default_monitor = "eDP-2"

Flake
- Remove blog, awesome-wallpapers and default-creds inputs (their repos
  no longer ship a flake.nix and broke `nix flake update`), along with
  the server modules and Glance links that used them
- Update flake.lock
- Replace removed `gcr` with `gcr_4`

Fixes
- Point configDirectory at /etc/nixos/nixy on home-pc and thinkpad
- Fix home-pc git email typo
- Remove conflicting openpgp signing format, make pull.rebase a boolean,
  replace hx/peco in git aliases with nvim/sk
- Fix zsh NUL alias (2>&1) and stop forcing bat colors in the cat alias
- Require a password for sudo again (nixos-rebuild stays NOPASSWD)
- Remove duplicate hardware.graphics block from home-pc flake
- Delete unused zen .old files, run alejandra on host files
2026-09-28 18:15:30 +02:00

61 lines
1.5 KiB
Nix

# Those are my secrets, encrypted with sops
# You shouldn't import this file, unless you edit it
{
inputs,
pkgs,
config,
lib,
...
}: let
hl = import ../../../home/system/hyprland/lib.nix {inherit lib;};
home = config.home.homeDirectory;
in {
imports = [inputs.sops-nix.homeManagerModules.sops];
sops = {
age.keyFile = "${home}/.config/sops/age/keys.txt";
defaultSopsFile = ./secrets.yaml;
secrets = {
ssh-config = {
path = "${home}/.ssh/config";
};
netrc = {
path = "${home}/.netrc";
};
github-key = {
path = "${home}/.ssh/github";
};
gitlab-key = {
path = "${home}/.ssh/gitlab";
};
};
};
home.file.".config/nixos/.sops.yaml".text = ''
keys:
- &primary age12yvtj49pfh3fqzqflscm0ek4yzrjhr6cqhn7x89gdxnlykq0xudq5c7334
- &work age1c8pawdsxptfslgrz2c56s39mrtnjzc5mm3hfzgr2wdwu2v6vfsdsupjsq6
creation_rules:
- path_regex: hosts/laptop/secrets/secrets.yaml$
key_groups:
- age:
- *primary
- path_regex: hosts/server/secrets/secrets.yaml$
key_groups:
- age:
- *primary
- path_regex: hosts/work/secrets/secrets.yaml$
key_groups:
- age:
- *work
'';
systemd.user.services.mbsync.Unit.After = ["sops-nix.service"];
home.packages = with pkgs; [
sops
age
];
wayland.windowManager.hyprland.settings.on = hl.execOnce ["systemctl --user start sops-nix"];
}