Compare commits

..

4 commits

Author SHA1 Message Date
67383019b7 Merge pull request 'nix flake update' (#92) from Gonne/nixConfig:updates into main
Reviewed-on: #92
Reviewed-by: nerf <nerf@noreply.localhost>
2025-06-26 13:07:50 +00:00
ed6f682085 nix flake update
Should fix in particular mailman (https://github.com/NixOS/nixpkgs/pull/418664)
2025-06-26 12:53:06 +02:00
7d88dfafa9 Merge pull request 'Enable cleartext diffs for SOPS secrets' (#90) from Gonne/nixConfig:cleartextdiff into main
Reviewed-on: #90
Reviewed-by: nerf <nerf@noreply.localhost>
2025-06-25 13:42:25 +00:00
8def445ac0 Enable cleartext diffs for SOPS secrets 2025-06-24 16:14:42 +02:00
4 changed files with 9 additions and 15 deletions

1
.gitattributes vendored Normal file
View file

@ -0,0 +1 @@
*.secrets.yaml diff=sopsdiffer

View file

@ -233,6 +233,8 @@ If the accessing process is not root it must be member of the group `config.user
for systemd services this can be archived by setting `serviceConfig.SupplementaryGroups = [ config.users.groups.keys.name ];`
it the service configuration.
For cleartext diffs configure your local clone with `git config diff.sopsdiffer.textconv "sops decrypt"` (see [Github](https://github.com/getsops/sops?tab=readme-ov-file#showing-diffs-in-cleartext-in-git)).
## impermanence
These machines are setup with `"/"` as a tmpfs. This is there to keep the machines clean. So no clutter in home

12
flake.lock generated
View file

@ -698,11 +698,11 @@
},
"nixpkgs_6": {
"locked": {
"lastModified": 1750506804,
"narHash": "sha256-VLFNc4egNjovYVxDGyBYTrvVCgDYgENp5bVi9fPTDYc=",
"lastModified": 1750776420,
"narHash": "sha256-/CG+w0o0oJ5itVklOoLbdn2dGB0wbZVOoDm4np6w09A=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "4206c4cb56751df534751b058295ea61357bbbaa",
"rev": "30a61f056ac492e3b7cdcb69c1e6abdcf00e39cf",
"type": "github"
},
"original": {
@ -819,11 +819,11 @@
"nixpkgs": []
},
"locked": {
"lastModified": 1749636823,
"narHash": "sha256-WUaIlOlPLyPgz9be7fqWJA5iG6rHcGRtLERSCfUDne4=",
"lastModified": 1750779888,
"narHash": "sha256-wibppH3g/E2lxU43ZQHC5yA/7kIKLGxVEnsnVK1BtRg=",
"owner": "cachix",
"repo": "pre-commit-hooks.nix",
"rev": "623c56286de5a3193aa38891a6991b28f9bab056",
"rev": "16ec914f6fb6f599ce988427d9d94efddf25fe6d",
"type": "github"
},
"original": {

View file

@ -38,15 +38,6 @@ with lib; let
"ocean.mathebau.de-1:G3Jz3mErIy8Mq8Ih+A5pbwDrx7vREcOpKgY8JCQ9dAk="
];
};
magnus = {
hashedPassword = "$6$54ip1KDxZCj6hWqm$.jIHeZ4iaoOkFZbx1z5Abb1YPW2vJ.R7mLqqYJgWCNRO26Xgkq4lilo/cWkRo7hRmiKamieEoQERbr0c6tAUH1";
sshKeys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILM7LCeZl1T2dd/+lnUlINhgCO6s4nJsrIs9pRs7gRpH mangus@pop-os"
];
nixKeys = [
"magnus:SNrfMnghIqVVD4QHiOiJEA1WtQ8Z15cyLTdPQeXZtR8="
];
};
};
mkAdmin = name: {