Samuel Shuert | 659b564 | 2024-02-23 20:47:43 +0000 | [diff] [blame] | 1 | nixpkgs: |
| 2 | let |
Samuel Shuert | 2e42e67 | 2024-02-21 21:49:28 +0000 | [diff] [blame] | 3 | keys = { |
| 4 | users = { |
| 5 | coded = "BC82DF237610AE9113EB075900E944BFBE99ADB5"; |
| 6 | minion = "76E0B09A741C4089522111E5F27E3E5922772E7A"; |
PineaFan | 3ed74f0 | 2024-04-20 20:41:36 +0100 | [diff] [blame] | 7 | pinea = "8F50789F12AC6E6206EA870CE5E1C2D43B0E4AB3"; |
Samuel Shuert | 2e42e67 | 2024-02-21 21:49:28 +0000 | [diff] [blame] | 8 | }; |
| 9 | hosts = { |
PineaFan | 3ed74f0 | 2024-04-20 20:41:36 +0100 | [diff] [blame] | 10 | # nix run github:Mic92/ssh-to-pgp -- -i /etc/ssh/ssh_host_rsa_key |
Samuel Shuert | 659b564 | 2024-02-23 20:47:43 +0000 | [diff] [blame] | 11 | shorthair = "B5237D6B63AB2E13FDA07170E5AED9775DD21543"; |
| 12 | greylag = "047bf8897df877fe86133e98522c6d280d545c00"; |
PineaFan | 3ed74f0 | 2024-04-20 20:41:36 +0100 | [diff] [blame] | 13 | saurosuchus = "12f47c96d9066c52897cdf9ddf581f86799fb07c"; |
Samuel Shuert | 2e42e67 | 2024-02-21 21:49:28 +0000 | [diff] [blame] | 14 | }; |
Samuel Shuert | 659b564 | 2024-02-23 20:47:43 +0000 | [diff] [blame] | 15 | }; |
| 16 | in |
| 17 | { |
Samuel Shuert | 2e42e67 | 2024-02-21 21:49:28 +0000 | [diff] [blame] | 18 | creation_rules = [ |
| 19 | { |
Samuel Shuert | 659b564 | 2024-02-23 20:47:43 +0000 | [diff] [blame] | 20 | path_regex = ".*\\.sops\\.chimera\\.(yaml|json|env|ini|[^.]*\\.bin)$"; |
Samuel Shuert | 2e42e67 | 2024-02-21 21:49:28 +0000 | [diff] [blame] | 21 | pgp = nixpkgs.lib.concatStringsSep "," [ |
| 22 | keys.users.coded |
| 23 | keys.users.minion |
PineaFan | 3ed74f0 | 2024-04-20 20:41:36 +0100 | [diff] [blame] | 24 | keys.users.pinea |
| 25 | |
Samuel Shuert | 2e42e67 | 2024-02-21 21:49:28 +0000 | [diff] [blame] | 26 | keys.hosts.shorthair |
| 27 | keys.hosts.greylag |
PineaFan | 3ed74f0 | 2024-04-20 20:41:36 +0100 | [diff] [blame] | 28 | keys.hosts.saurosuchus |
Samuel Shuert | 2e42e67 | 2024-02-21 21:49:28 +0000 | [diff] [blame] | 29 | ]; |
| 30 | } |
| 31 | { |
Samuel Shuert | 659b564 | 2024-02-23 20:47:43 +0000 | [diff] [blame] | 32 | path_regex = ".*\\.sops\\.coded\\.(yaml|json|env|ini|[^.]*\\.bin)$"; |
Samuel Shuert | 2e42e67 | 2024-02-21 21:49:28 +0000 | [diff] [blame] | 33 | pgp = nixpkgs.lib.concatStringsSep "," [ |
| 34 | keys.users.coded |
| 35 | keys.hosts.shorthair |
| 36 | ]; |
| 37 | } |
| 38 | { |
Samuel Shuert | 659b564 | 2024-02-23 20:47:43 +0000 | [diff] [blame] | 39 | path_regex = ".*\\.sops\\.minion\\.(yaml|json|env|ini|[^.]*\\.bin)$"; |
Samuel Shuert | 2e42e67 | 2024-02-21 21:49:28 +0000 | [diff] [blame] | 40 | pgp = nixpkgs.lib.concatStringsSep "," [ |
| 41 | keys.users.minion |
| 42 | keys.hosts.greylag |
| 43 | ]; |
| 44 | } |
PineaFan | 3ed74f0 | 2024-04-20 20:41:36 +0100 | [diff] [blame] | 45 | { |
| 46 | path_regex = ".*\\.sops\\.pinea\\.(yaml|json|env|ini|[^.]*\\.bin)$"; |
| 47 | pgp = nixpkgs.lib.concatStringsSep "," [ |
| 48 | keys.users.pinea |
| 49 | keys.hosts.saurosuchus |
| 50 | ]; |
| 51 | } |
Samuel Shuert | 2e42e67 | 2024-02-21 21:49:28 +0000 | [diff] [blame] | 52 | ]; |
Samuel Shuert | 659b564 | 2024-02-23 20:47:43 +0000 | [diff] [blame] | 53 | } |