fix(surgat): ssh initrd unlock

This commit is contained in:
Tim Schubert 2025-05-17 14:01:36 +02:00
parent cb69d8edb0
commit 33bc06ee10
No known key found for this signature in database
3 changed files with 3 additions and 2 deletions

View file

@ -1,7 +1,7 @@
{ config, lib, ... }: { config, lib, ... }:
let let
secretsPath = config.dadada.secrets.path; secretsPath = config.dadada.secrets.path;
initrdHostKey = "${config.networking.hostName}-ssh_host_ed25519_key"; initrdHostKey = "${config.networking.hostName}-initrd-ssh_host_ed25519_key";
in in
{ {
boot.initrd.availableKernelModules = [ "virtio-pci" ]; boot.initrd.availableKernelModules = [ "virtio-pci" ];
@ -9,7 +9,7 @@ in
enable = true; enable = true;
ssh = { ssh = {
enable = true; enable = true;
port = 22; port = 2223;
hostKeys = [ hostKeys = [
config.age.secrets."${initrdHostKey}".path config.age.secrets."${initrdHostKey}".path
]; ];

View file

@ -21,6 +21,7 @@ in
"miniflux-admin-credentials.age".publicKeys = [ systems.surgat dadada ]; "miniflux-admin-credentials.age".publicKeys = [ systems.surgat dadada ];
"gorgon-backup-passphrase-gs.age".publicKeys = [ systems.gorgon dadada ]; "gorgon-backup-passphrase-gs.age".publicKeys = [ systems.gorgon dadada ];
"paperless.age".publicKeys = [ systems.gorgon dadada ]; "paperless.age".publicKeys = [ systems.gorgon dadada ];
"surgat-initrd-ssh_host_ed25519_key.age".publicKeys = [ systems.surgat dadada ];
"surgat-ssh_host_ed25519_key.age".publicKeys = [ systems.surgat dadada ]; "surgat-ssh_host_ed25519_key.age".publicKeys = [ systems.surgat dadada ];
"ninurta-initrd-ssh-key.age".publicKeys = [ systems.ninurta dadada ]; "ninurta-initrd-ssh-key.age".publicKeys = [ systems.ninurta dadada ];
"ddns-credentials.age".publicKeys = [ systems.agares systems.ninurta dadada ]; "ddns-credentials.age".publicKeys = [ systems.agares systems.ninurta dadada ];

Binary file not shown.