diff --git a/flake.lock b/flake.lock index 9c31da9..19d0c94 100644 --- a/flake.lock +++ b/flake.lock @@ -366,6 +366,7 @@ "nix-ai-tools": "nix-ai-tools", "nixpkgs": "nixpkgs_2", "nvim-bundle": "nvim-bundle", + "sops-nix": "sops-nix", "zig-overlay": "zig-overlay" } }, @@ -391,6 +392,26 @@ "type": "github" } }, + "sops-nix": { + "inputs": { + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1759188042, + "narHash": "sha256-f9QC2KKiNReZDG2yyKAtDZh0rSK2Xp1wkPzKbHeQVRU=", + "owner": "Mic92", + "repo": "sops-nix", + "rev": "9fcfabe085281dd793589bdc770a2e577a3caa5d", + "type": "github" + }, + "original": { + "owner": "Mic92", + "repo": "sops-nix", + "type": "github" + } + }, "systems": { "locked": { "lastModified": 1681028828, diff --git a/flake.nix b/flake.nix index d64705e..1f2304e 100644 --- a/flake.nix +++ b/flake.nix @@ -25,8 +25,8 @@ zig-overlay.inputs.nixpkgs.follows = "nixpkgs"; }; - outputs = - inputs@{ self, nixpkgs, darwin, home-manager, ghostty, nix-ai-tools, sops-nix, ... }: + outputs = inputs@{ self, nixpkgs, darwin, home-manager, ghostty, nix-ai-tools + , sops-nix, ... }: let inherit (nixpkgs.lib) genAttrs; lib = nixpkgs.lib; diff --git a/modules/home/rsydn/secrets.nix b/modules/home/rsydn/secrets.nix index 002bf27..6d23eb7 100644 --- a/modules/home/rsydn/secrets.nix +++ b/modules/home/rsydn/secrets.nix @@ -6,19 +6,19 @@ let sanitizeSecret = name: secret: let sopsFile = secret.sopsFile or cfg.defaultSopsFile; - extra = lib.filterAttrs (k: _: !(builtins.elem k [ "path" "mode" "sopsFile" ])) secret; - in - { + extra = + lib.filterAttrs (k: _: !(builtins.elem k [ "path" "mode" "sopsFile" ])) + secret; + in { path = secret.path or "${config.xdg.configHome}/secrets/${name}"; mode = secret.mode or "0400"; - } - // (lib.optionalAttrs (sopsFile != null) { inherit sopsFile; }) - // extra; + } // (lib.optionalAttrs (sopsFile != null) { inherit sopsFile; }) // extra; in { imports = [ inputs.sops-nix.homeManagerModules.sops ]; options.rsydn.secrets = { - enable = mkEnableOption "sops-nix integration for managing decrypted secrets"; + enable = + mkEnableOption "sops-nix integration for managing decrypted secrets"; ageKeyFile = mkOption { type = types.str; @@ -29,13 +29,15 @@ in { defaultSopsFile = mkOption { type = types.nullOr types.path; default = null; - description = "Optional default SOPS file used when a secret definition omits `sopsFile`."; + description = + "Optional default SOPS file used when a secret definition omits `sopsFile`."; }; secrets = mkOption { type = types.attrsOf types.attrs; default = { }; - description = "Secret entries forwarded to `sops.secrets` with sensible defaults."; + description = + "Secret entries forwarded to `sops.secrets` with sensible defaults."; example = lib.literalExpression '' { "api-key" = { @@ -49,22 +51,21 @@ in { }; config = mkIf cfg.enable { - sops = - { - age = { - keyFile = cfg.ageKeyFile; - generateKey = true; - }; + sops = { + age = { + keyFile = cfg.ageKeyFile; + generateKey = true; + }; - secrets = lib.mapAttrs sanitizeSecret cfg.secrets; - } - // (lib.optionalAttrs (cfg.defaultSopsFile != null) { - defaultSopsFile = cfg.defaultSopsFile; - }); + secrets = lib.mapAttrs sanitizeSecret cfg.secrets; + } // (lib.optionalAttrs (cfg.defaultSopsFile != null) { + defaultSopsFile = cfg.defaultSopsFile; + }); - home.activation.ensureSecretDir = lib.hm.dag.entryAfter [ "writeBoundary" ] '' - mkdir -p "${config.xdg.configHome}/secrets" - chmod 700 "${config.xdg.configHome}/secrets" - ''; + home.activation.ensureSecretDir = + lib.hm.dag.entryAfter [ "writeBoundary" ] '' + mkdir -p "${config.xdg.configHome}/secrets" + chmod 700 "${config.xdg.configHome}/secrets" + ''; }; }