muliple(teal): Update teal
feat: Add a.starrysky.blog
feat: re-key keys with shorthairNanoResident age key
chore: update packages
fix: redo headscale options
Change-Id: I27cab9abc4622f0a69811e35d4e0eb87af29b42b
Reviewed-on: https://git.clicks.codes/c/Infra/NixFiles/+/981
Reviewed-by: Skyler Grey <minion@clicks.codes>
Tested-by: Skyler Grey <minion@clicks.codes>
diff --git a/modules/nixos/clicks/security/secrets/default.nix b/modules/nixos/clicks/security/secrets/default.nix
index 8a120f9..b165d7b 100644
--- a/modules/nixos/clicks/security/secrets/default.nix
+++ b/modules/nixos/clicks/security/secrets/default.nix
@@ -16,10 +16,14 @@
config.age = lib.optionalAttrs cfg.enable {
rekey = {
- masterIdentities = [
- "${inputs.self}/secrets/keys/minion/collabora-yubikey.pub"
- "${inputs.self}/secrets/keys/minion/tiny-yubikey.pub"
- "${inputs.self}/secrets/keys/minion/iyubikey.pub"
+ masterIdentities =
+ let
+ keyPath = "${inputs.self}/secrets/keys";
+ in [
+ "${keyPath}/minion/collabora-yubikey.pub"
+ "${keyPath}/minion/tiny-yubikey.pub"
+ "${keyPath}/minion/iyubikey.pub"
+ "${keyPath}/coded/ShorthairNano.pub"
];
storageMode = "local";
generatedSecretsDir = lib.snowfall.fs.get-snowfall-file "secrets/generated/${config.networking.hostName}";