feat: add agenix, some secrets and dyndns user

This commit is contained in:
2026-02-08 18:26:03 +01:00
parent 3a1ebbcb66
commit 39952ecd6e
8 changed files with 166 additions and 6 deletions
Generated
+85 -3
View File
@@ -1,5 +1,50 @@
{ {
"nodes": { "nodes": {
"agenix": {
"inputs": {
"darwin": "darwin",
"home-manager": "home-manager",
"nixpkgs": [
"nixpkgs"
],
"systems": "systems"
},
"locked": {
"lastModified": 1770165109,
"narHash": "sha256-9VnK6Oqai65puVJ4WYtCTvlJeXxMzAp/69HhQuTdl/I=",
"owner": "ryantm",
"repo": "agenix",
"rev": "b027ee29d959fda4b60b57566d64c98a202e0feb",
"type": "github"
},
"original": {
"owner": "ryantm",
"repo": "agenix",
"type": "github"
}
},
"darwin": {
"inputs": {
"nixpkgs": [
"agenix",
"nixpkgs"
]
},
"locked": {
"lastModified": 1744478979,
"narHash": "sha256-dyN+teG9G82G+m+PX/aSAagkC+vUv0SgUw3XkPhQodQ=",
"owner": "lnl7",
"repo": "nix-darwin",
"rev": "43975d782b418ebf4969e9ccba82466728c2851b",
"type": "github"
},
"original": {
"owner": "lnl7",
"ref": "master",
"repo": "nix-darwin",
"type": "github"
}
},
"flake-parts": { "flake-parts": {
"inputs": { "inputs": {
"nixpkgs-lib": [ "nixpkgs-lib": [
@@ -23,7 +68,7 @@
}, },
"flake-utils": { "flake-utils": {
"inputs": { "inputs": {
"systems": "systems" "systems": "systems_2"
}, },
"locked": { "locked": {
"lastModified": 1731533236, "lastModified": 1731533236,
@@ -40,6 +85,27 @@
} }
}, },
"home-manager": { "home-manager": {
"inputs": {
"nixpkgs": [
"agenix",
"nixpkgs"
]
},
"locked": {
"lastModified": 1745494811,
"narHash": "sha256-YZCh2o9Ua1n9uCvrvi5pRxtuVNml8X2a03qIFfRKpFs=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "abfad3d2958c9e6300a883bd443512c55dfeb1be",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "home-manager",
"type": "github"
}
},
"home-manager_2": {
"inputs": { "inputs": {
"nixpkgs": [ "nixpkgs": [
"nixpkgs" "nixpkgs"
@@ -127,7 +193,7 @@
"nixpkgs" "nixpkgs"
], ],
"nuschtosSearch": "nuschtosSearch", "nuschtosSearch": "nuschtosSearch",
"systems": "systems_2" "systems": "systems_3"
}, },
"locked": { "locked": {
"lastModified": 1767448089, "lastModified": 1767448089,
@@ -169,7 +235,8 @@
}, },
"root": { "root": {
"inputs": { "inputs": {
"home-manager": "home-manager", "agenix": "agenix",
"home-manager": "home-manager_2",
"nixpkgs": "nixpkgs", "nixpkgs": "nixpkgs",
"nixpkgs-unstable": "nixpkgs-unstable", "nixpkgs-unstable": "nixpkgs-unstable",
"nixvim": "nixvim" "nixvim": "nixvim"
@@ -204,6 +271,21 @@
"repo": "default", "repo": "default",
"type": "github" "type": "github"
} }
},
"systems_3": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
} }
}, },
"root": "root", "root": "root",
+3
View File
@@ -8,6 +8,9 @@
nixvim.url = "github:nix-community/nixvim/nixos-25.11"; nixvim.url = "github:nix-community/nixvim/nixos-25.11";
nixvim.inputs.nixpkgs.follows = "nixpkgs"; nixvim.inputs.nixpkgs.follows = "nixpkgs";
agenix.url = "github:ryantm/agenix";
agenix.inputs.nixpkgs.follows = "nixpkgs";
}; };
outputs = outputs =
+37 -3
View File
@@ -1,22 +1,53 @@
{ {
inputs, inputs,
outputs, outputs,
config,
pkgs,
... ...
}: }:
let
dyndnsScript = pkgs.writeScript "dyndns.py" (builtins.readFile ./dyndns.py);
in
{ {
imports = [ imports = [
(import ../base.nix { inherit inputs outputs; }) (import ../base.nix { inherit inputs outputs; })
./hardware-configuration.nix ./hardware-configuration.nix
./secrets
inputs.agenix.nixosModules.default
]; ];
users.groups.dyndns = { };
users.users = { users.users = {
leonhard = { leonhard = {
initialPassword = "leonhard"; initialPassword = "leonhard";
isNormalUser = true; isNormalUser = true;
extraGroups = [ "wheel" ]; extraGroups = [ "wheel" ];
openssh.authorizedKeys.keys = [ openssh.authorizedKeys.keys = config.kekleo.publicKeys;
"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDPegeAIABaY9DyWumihNZBlzfdduycvurwYYqoZrdkov2pRVJt8eFhXe+5tdLTKiAq58yzkJ6Zj3CuYb3XuQxX/aDvY4covDXjn1tGKf32xkhTuLd9eDGbFishiC+qROp2/3eZ01DwuttHWo3n/jwOwL3M9mw9Now2i2qaTGuq8wfG5XJ9Cp2+3Ly+mChhtff7Us65dWihNbR3k2WLLvdPJ2HMjeZder0u/IsTTGJj/sytEGt0LPqFOJMl0QuqemkzbeoSAEpVl4huXp5LVT7be2UUmRuekg0p2+EopHunMhUaf7dekiupbKFFNY8aU/eOEZmnakJpOEhcZWaFot825O8jViC9I0NTLazgwttqnZxnuFIp/0Ljf0j7SR/tJa55T0yMH5pyEjw/yvYLplJKbBlPyl2LpsN37l5HKXFtunOsiK/NLL6rLUoTjO5QGCg750c2UKqL8A1g11sW82kscePQTFKbIRmr271ruFWaxnNNh2W5LuJNcUlLf/t/6ps= leonhard" };
]; dyndns = {
isSystemUser = true;
group = "dyndns";
packages = [ pkgs.python313Packages.nc-dnsapi ];
};
};
systemd.timers."dyndns" = {
wantedBy = [ "timers.target" ];
timerConfig = {
OnBootSec = "5m";
OnUnitActiveSec = "5m";
Unit = "dyndns.service";
};
};
systemd.services."dyndns" = {
script = ''
set -eu
${pkgs.python313}/bin/python3 ${dyndnsScript}
'';
serviceConfig = {
Type = "oneshot";
User = "dyndns";
}; };
}; };
@@ -52,4 +83,7 @@
}; };
kekleo.graphical = false; kekleo.graphical = false;
kekleo.publicKeys = [
"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDPegeAIABaY9DyWumihNZBlzfdduycvurwYYqoZrdkov2pRVJt8eFhXe+5tdLTKiAq58yzkJ6Zj3CuYb3XuQxX/aDvY4covDXjn1tGKf32xkhTuLd9eDGbFishiC+qROp2/3eZ01DwuttHWo3n/jwOwL3M9mw9Now2i2qaTGuq8wfG5XJ9Cp2+3Ly+mChhtff7Us65dWihNbR3k2WLLvdPJ2HMjeZder0u/IsTTGJj/sytEGt0LPqFOJMl0QuqemkzbeoSAEpVl4huXp5LVT7be2UUmRuekg0p2+EopHunMhUaf7dekiupbKFFNY8aU/eOEZmnakJpOEhcZWaFot825O8jViC9I0NTLazgwttqnZxnuFIp/0Ljf0j7SR/tJa55T0yMH5pyEjw/yvYLplJKbBlPyl2LpsN37l5HKXFtunOsiK/NLL6rLUoTjO5QGCg750c2UKqL8A1g11sW82kscePQTFKbIRmr271ruFWaxnNNh2W5LuJNcUlLf/t/6ps= leonhard@LeonhardsPC"
];
} }
+3
View File
@@ -0,0 +1,3 @@
from nc_dnsapi import Client, DNSRecord
pass
+25
View File
@@ -0,0 +1,25 @@
{
config,
pkgs,
...
}:
let
keys = builtins.map (
key: builtins.toString (pkgs.writeText "agenix-key" key)
) config.kekleo.publicKeys;
in
{
age.identityPaths = keys;
age.secrets.nc_customer = {
file = ./nc_customer.age;
owner = "dyndns";
};
age.secrets.nc_api_password = {
file = ./nc_api_password.age;
owner = "dyndns";
};
age.secrets.nc_api_key = {
file = ./nc_api_key.age;
owner = "dyndns";
};
}
+13
View File
@@ -0,0 +1,13 @@
age-encryption.org/v1
-> ssh-rsa 0VNryQ
YH11o9QzKg5u12VpNWVth66TStPbNM1A5LEc2iERk6pt3mh3gMFZ4dY0xCi8unaY
C1xeNd0dmxJwbeCVmEy7zj8IQ9ROAhobv0uFGDJHuqr96HoMxk3iw2/M5up3KCFc
w6cdJWVJzG0UP20Jiu3f3Yw5dCt7bGGr4MWL9XNmzOzXZEfBcnPiXgdhwurRfOR/
ZR/r06uNzJNb9nyZeAewU4B1WtkfGdzw6T44IheTmXjTSP2woFl64vddnayl64lw
xnoG85jz23ayiB8IDIkE+o5cb/2kfPCQNG3JVd+XGT3SJvJRYHwFl6hfX63G504A
6UzCHMrKG8WeNg0WwR4ViyoEg3Q0ZsExCxBx7itB0/7i/Q4v3bcif1jFFIC2HepC
5M9UcYlHr06qkfITHATnq3pCd+0piolT7k3YwFzeojp/zUUtfnMOFauVNpeEfqy4
B5deqnbKYt8z0BZsZ377RUbsP7q+Xho6dZmVOEqG3LzzW3aJSbhigduh51vCbimD
--- yMIQCO5AwTLnXoHXjYHBvXfOIf5vRe/cmNv4mzqlU6s
bü¥°<ÕQXH O0q†w¿üç®Ô³‡w$ lyg]¿ÇõñâÒŠ›Άþ´gÇÑH␍Z"ÉÇn³Q&-U_2ÎõN.–ärg»·™ö3€
Binary file not shown.
Binary file not shown.