fix: recreate with raw content (was double-base64'd)
This commit is contained in:
39
hosts/blade/default.nix
Normal file
39
hosts/blade/default.nix
Normal file
@@ -0,0 +1,39 @@
|
||||
{ pkgs, ... }:
|
||||
{
|
||||
imports = [
|
||||
./hardware-configuration.nix
|
||||
./networking.nix
|
||||
./users.nix
|
||||
./power-plan.nix
|
||||
../../modules/common/incus.nix
|
||||
];
|
||||
|
||||
# ── Docker host inside Incus ──
|
||||
services.docker-host-incus.enable = true;
|
||||
services.docker-host-incus.ip = "10.0.0.2";
|
||||
|
||||
networking.interfaces.eth0.wakeOnLan.enable = true;
|
||||
|
||||
# ── NetBird zero-trust VPN ─────────────────────────────────
|
||||
services.netbird = {
|
||||
enable = true;
|
||||
login = {
|
||||
enable = true;
|
||||
setupKeyFile = "/run/secrets/netbird-setup-key";
|
||||
};
|
||||
};
|
||||
|
||||
# Decrypt the NetBird setup key from SOPS secrets before netbird starts
|
||||
system.activationScripts.netbird-setup-key = {
|
||||
text = ''
|
||||
mkdir -p /run/secrets
|
||||
${pkgs.sops}/bin/sops \
|
||||
--decrypt \
|
||||
--extract '["netbird_setup_key"]' \
|
||||
${./secrets.yaml} \
|
||||
> /run/secrets/netbird-setup-key
|
||||
chmod 600 /run/secrets/netbird-setup-key
|
||||
'';
|
||||
deps = [ "etc" ];
|
||||
};
|
||||
}
|
||||
Reference in New Issue
Block a user