fixed secret perms

This commit is contained in:
Adrian Gunnar Lauterer 2023-12-10 18:34:28 +01:00
parent 0903e94482
commit 168197505d
2 changed files with 7 additions and 2 deletions

View File

@ -25,7 +25,5 @@
# This is the actual specification of the secrets.
#sops.secrets."myservice/my_subdir/my_secret" = {};
sops.secrets."acme/certs" = { };
sops.secrets."nginx/defaultpass" = { };
}

View File

@ -19,6 +19,13 @@
users.users.nginx.extraGroups = [ "acme" ];
users.users.root.extraGroups = [ "acme" ];
#declare secrets
sops.secrets."acme/certs" = { };
sops.secrets."nginx/defaultpass" = {
restartUnits = [ "nginx.service" ];
owner = "nginx";
};
#TODO add oauth2 proxy to auth
# services.oauth2_proxy = {
# enable = true;