diff --git a/provision/modules/system/secrets.nix b/provision/modules/system/secrets.nix index 58cf3a07..1a8bb44b 100644 --- a/provision/modules/system/secrets.nix +++ b/provision/modules/system/secrets.nix @@ -15,5 +15,15 @@ in { owner = "${user}"; group = "users"; }; + age.secrets."ssh/kestrel/id_ed25519" = { + file = ../../secrets/ssh/kestrel/id_ed25519.age; + owner = "${user}"; + group = "users"; + }; + age.secrets."ssh/kestrel/id_ed25519.pub" = { + file = ../../secrets/ssh/kestrel/id_ed25519.pub.age; + owner = "${user}"; + group = "users"; + }; }; } diff --git a/provision/secrets/secrets.nix b/provision/secrets/secrets.nix index 6e0842af..29b705e1 100644 --- a/provision/secrets/secrets.nix +++ b/provision/secrets/secrets.nix @@ -14,4 +14,6 @@ in "wireguard/bulwark.age".publicKeys = systems; "git/gitea-runner-1.age".publicKeys = systems; "nextcloud/password.age".publicKeys = systems; + "ssh/kestrel/id_ed25519.age".publicKeys = [ tstarr_kestrel ] ++ systems; + "ssh/kestrel/id_ed25519.pub.age".publicKeys = [ tstarr_kestrel ] ++ systems; } diff --git a/provision/secrets/ssh/kestrel/id_ed25519.age b/provision/secrets/ssh/kestrel/id_ed25519.age new file mode 100644 index 00000000..cbcc218d Binary files /dev/null and b/provision/secrets/ssh/kestrel/id_ed25519.age differ diff --git a/provision/secrets/ssh/kestrel/id_ed25519.pub.age b/provision/secrets/ssh/kestrel/id_ed25519.pub.age new file mode 100644 index 00000000..779cd2ff --- /dev/null +++ b/provision/secrets/ssh/kestrel/id_ed25519.pub.age @@ -0,0 +1,10 @@ +age-encryption.org/v1 +-> ssh-ed25519 c/r/0Q +D6/eizW8sHinmD3T1GcRHbykaKpTLg/LA/TVwtcKE8 +OMZiDpnclm43THtvOMS1yty6TGd+uhY3pXZ4Ki+P8Cc +-> ssh-ed25519 Fz/sQw 7nGnk473hfSh/ZuDxaFcrTBjYg93blJJyhfz/g5NuGM +bwdjYVzIi8djVzkS2FOgL1V/zi/nNszxXg9EHo9Z7T0 +-> ssh-ed25519 47GzQA lm5EIYLobeJyOmvSW9GPU2V+7KAGBEJXJ0TqHx3ABVQ +gnl/k+gfXEUqleiJWQipLOrhVcJljEMp2mbC+irGkJA +--- K/QSHLrouRPDlm0mesa1wk9rOS9sjK1lmVhzHLj4VqM +Úx‘…<ÜŒy[€ %[!iÉûs}ËÒI¬Žðì¸hd”žxÖ 2s +‰ ÷^Ø6èé5ÆhAºÍ?ÖWå~¢ â¯Ï’g$¶=UØ\E’¤ÑÒ˜I@Æc¿ýt$õÆ- 6y *â+A[§À<Êß³ÛK \ No newline at end of file