fix(surgat): ssh initrd unlock

This commit is contained in:
Tim Schubert 2025-05-17 14:01:36 +02:00
parent cb69d8edb0
commit 33bc06ee10
No known key found for this signature in database
3 changed files with 3 additions and 2 deletions

View file

@ -1,7 +1,7 @@
{ config, lib, ... }:
let
secretsPath = config.dadada.secrets.path;
initrdHostKey = "${config.networking.hostName}-ssh_host_ed25519_key";
initrdHostKey = "${config.networking.hostName}-initrd-ssh_host_ed25519_key";
in
{
boot.initrd.availableKernelModules = [ "virtio-pci" ];
@ -9,7 +9,7 @@ in
enable = true;
ssh = {
enable = true;
port = 22;
port = 2223;
hostKeys = [
config.age.secrets."${initrdHostKey}".path
];

View file

@ -21,6 +21,7 @@ in
"miniflux-admin-credentials.age".publicKeys = [ systems.surgat dadada ];
"gorgon-backup-passphrase-gs.age".publicKeys = [ systems.gorgon dadada ];
"paperless.age".publicKeys = [ systems.gorgon dadada ];
"surgat-initrd-ssh_host_ed25519_key.age".publicKeys = [ systems.surgat dadada ];
"surgat-ssh_host_ed25519_key.age".publicKeys = [ systems.surgat dadada ];
"ninurta-initrd-ssh-key.age".publicKeys = [ systems.ninurta dadada ];
"ddns-credentials.age".publicKeys = [ systems.agares systems.ninurta dadada ];

Binary file not shown.