Try To Get a Secret Decrypted Into a File

This commit is contained in:
Annika Merris 2024-05-12 10:32:27 -04:00
parent adf43c6bf5
commit affa3000d7
3 changed files with 42 additions and 3 deletions

View file

@ -1,9 +1,18 @@
{ config, pkgs, ... }:
{
# imports = [
# inputs.sops-nix.homeManagerModules.sops
#];
imports = [
inputs.sops-nix.homeManagerModules.sops
];
# Configure secrets stuff
sops = {
defaultSopsFile = "../../secrets.yaml";
defaultSopsFormat = "yaml";
age.keyFile = "/home/annika/.config/sops/age/keys.txt";
secrets."spotifyd/settings/global/password" = { };
};
nixpkgs.config.allowUnfree = true;
# Home Manager needs a bit of information about you and the paths it should

View file

@ -0,0 +1,6 @@
[global]
username = "me@annikamerris.com"
password_cmd = "something"
use_mpris = true
device_name = "kim-nix"
device_type = "computer"

24
secrets/secrets.yaml Normal file
View file

@ -0,0 +1,24 @@
spotifyd:
settings:
global:
password: ENC[AES256_GCM,data:YnfXoQ7pbqoZ8QcqfkYd3A==,iv:+QwDqlZ5HEIasmeMAT48kvF3LpbTzJMu4OR1kjWOZCQ=,tag:rANAqr1GlYzHNItb2AmCmg==,type:str]
sops:
kms: []
gcp_kms: []
azure_kv: []
hc_vault: []
age:
- recipient: age1e8wfn0vmwv506n060hzqkwhsekykynl9tpatnm2swhew30kmuyest0slhv
enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBCK0l0S1VtRUlqRW54TU1F
R09WSEpvaVhLaWp3bEd2bnJ4Y3o3eEVobVU0CnN2ak50cTdkSHVqWlg4RlV5Q0cx
VEFpQ3VqZ1NNSiswMEFhVkVFOFRxWHcKLS0tIDZYM1hHN2poSjdZcnZZVTZITWFL
Mzd6MnNDSUJoQ2w3dEhDdkpxR2pnZUkKXgKr/jE6ZVzJGF3DzyKfyAlF89CEbpxH
maKt3YwaPfQwiV5leDo26tOMXs/CB1fiRcjN80ByeoS7uHevsbdAyw==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2024-05-12T13:52:54Z"
mac: ENC[AES256_GCM,data:m/6tsxQDl+Ox+pWlWb46GvO49pTdzVNrDhaNlEHZ8clwqCqGB0onUJR8rWI8dVIeEyCqXhQ5dHn6B0QMJcyAxhLd6R8fc193hSmv7e5oBm5Qj0L1sd83lQRhrcFyM1qUpJzQydWVlp7vQFqpLzNqsQ6ZwH0r3hK4eRaqS4GaNfo=,iv:j+5mN1yI00Tdii2cfN3imbB56msfB0wUZ/ANNW143jo=,tag:ROQfmDd2uq0zvIX6FhwyTQ==,type:str]
pgp: []
unencrypted_suffix: _unencrypted
version: 3.8.1