My Nix Configuration

[marvin.forgejo] move secrets to subdir

pyrox.dev fcfc35e5 011ddff1

verified
+9 -9
systems/x86_64-linux/marvin/services/git.nix
···
};
age.secrets = {
forgejo-db-pw = forgejoSecret // {
-
file = ./secrets/forgejo-db-pw.age;
+
file = ./secrets/forgejo/db-pw.age;
};
forgejo-mail-pw = forgejoSecret // {
-
file = ./secrets/forgejo-mail-pw.age;
+
file = ./secrets/forgejo/mail-pw.age;
};
forgejo-aux-docs-runner-token = forgejoSecret // {
-
file = ./secrets/forgejo-aux-docs-runner-token.age;
+
file = ./secrets/forgejo/aux-docs-runner-token.age;
};
forgejo-default-runner-token = forgejoSecret // {
-
file = ./secrets/forgejo-default-runner-token.age;
+
file = ./secrets/forgejo/default-runner-token.age;
};
forgejo-gitgay-runner-token = forgejoSecret // {
-
file = ./secrets/forgejo-gitgay-runner-token.age;
+
file = ./secrets/forgejo/gitgay-runner-token.age;
};
forgejo-internal-token = forgejoSecret // {
-
file = ./secrets/forgejo-internal-token.age;
+
file = ./secrets/forgejo/internal-token.age;
};
forgejo-oauth2-jwt-secret = forgejoSecret // {
-
file = ./secrets/forgejo-oauth2-jwt-secret.age;
+
file = ./secrets/forgejo/oauth2-jwt-secret.age;
};
forgejo-lfs-jwt-secret = forgejoSecret // {
-
file = ./secrets/forgejo-lfs-jwt-secret.age;
+
file = ./secrets/forgejo/lfs-jwt-secret.age;
};
forgejo-secret-key = forgejoSecret // {
-
file = ./secrets/forgejo-secret-key.age;
+
file = ./secrets/forgejo/secret-key.age;
};
};
services.anubis.instances.forgejo = {
systems/x86_64-linux/marvin/services/secrets/forgejo-aux-docs-runner-token.age systems/x86_64-linux/marvin/services/secrets/forgejo/aux-docs-runner-token.age
systems/x86_64-linux/marvin/services/secrets/forgejo-db-pw.age systems/x86_64-linux/marvin/services/secrets/forgejo/db-pw.age
systems/x86_64-linux/marvin/services/secrets/forgejo-default-runner-token.age systems/x86_64-linux/marvin/services/secrets/forgejo/default-runner-token.age
systems/x86_64-linux/marvin/services/secrets/forgejo-gitgay-runner-token.age systems/x86_64-linux/marvin/services/secrets/forgejo/gitgay-runner-token.age
systems/x86_64-linux/marvin/services/secrets/forgejo-internal-token.age systems/x86_64-linux/marvin/services/secrets/forgejo/internal-token.age
systems/x86_64-linux/marvin/services/secrets/forgejo-lfs-jwt-secret.age systems/x86_64-linux/marvin/services/secrets/forgejo/lfs-jwt-secret.age
systems/x86_64-linux/marvin/services/secrets/forgejo-mail-pw.age systems/x86_64-linux/marvin/services/secrets/forgejo/mail-pw.age
systems/x86_64-linux/marvin/services/secrets/forgejo-oauth2-jwt-secret.age systems/x86_64-linux/marvin/services/secrets/forgejo/oauth2-jwt-secret.age
systems/x86_64-linux/marvin/services/secrets/forgejo-secret-key.age systems/x86_64-linux/marvin/services/secrets/forgejo/secret-key.age
+9 -9
systems/x86_64-linux/marvin/services/secrets/secrets.nix
···
"buildbot-gitea-token.age".publicKeys = marvinDefault;
"buildbot-oauth-secret.age".publicKeys = marvinDefault;
"buildbot-workers.age".publicKeys = marvinDefault;
-
"forgejo-db-pw.age".publicKeys = marvinDefault;
-
"forgejo-mail-pw.age".publicKeys = marvinDefault;
-
"forgejo-aux-docs-runner-token.age".publicKeys = marvinDefault;
-
"forgejo-default-runner-token.age".publicKeys = marvinDefault;
-
"forgejo-gitgay-runner-token.age".publicKeys = marvinDefault;
-
"forgejo-internal-token.age".publicKeys = marvinDefault;
-
"forgejo-lfs-jwt-secret.age".publicKeys = marvinDefault;
-
"forgejo-oauth2-jwt-secret.age".publicKeys = marvinDefault;
-
"forgejo-secret-key.age".publicKeys = marvinDefault;
+
"forgejo/aux-docs-runner-token.age".publicKeys = marvinDefault;
+
"forgejo/db-pw.age".publicKeys = marvinDefault;
+
"forgejo/default-runner-token.age".publicKeys = marvinDefault;
+
"forgejo/gitgay-runner-token.age".publicKeys = marvinDefault;
+
"forgejo/internal-token.age".publicKeys = marvinDefault;
+
"forgejo/lfs-jwt-secret.age".publicKeys = marvinDefault;
+
"forgejo/mail-pw.age".publicKeys = marvinDefault;
+
"forgejo/oauth2-jwt-secret.age".publicKeys = marvinDefault;
+
"forgejo/secret-key.age".publicKeys = marvinDefault;
"golink-authkey.age".publicKeys = marvinDefault;
"grafana-admin-password.age".publicKeys = marvinDefault;
"grafana-smtp-password.age".publicKeys = marvinDefault;