Compare commits

..

1 commit

Author SHA1 Message Date
d74be71aa1
added keys so nodens can sign builds 2025-06-22 20:12:59 +02:00

View file

@ -34,10 +34,10 @@
# right now it is only nodens so nodens can build system configs
# and we can deploy them from nodens.
# For security reasons we might want to move this to the vm part, as
# someone who can get controll of nodens and get hold of the build process
# someone who can get control of nodens and get hold of the build process
# can gain control of the other machines. While this is very handy
# and a step towards CI, we might not want this for backups.
# (This is a tradeof between security and convinience)
# (This is a tradeof between security and convenience)
nix.settings.trusted-public-keys = ["nodens-deploy.key:VHJmEr17pdoEEnWlSfC03TIf4GBbClxGRiInHuWaUvU="];
environment = {