2283ee602a
This enables the tracking of core-services-01 over the infrastructure repository. Co-authored-by: Gabriel DORIATH DOHLER <gabriel.doriath.dohler@ens.psl.eu> Reviewed-on: https://git.rz.ens.wtf/Klub-RZ/infrastructure/pulls/1 Co-authored-by: raito <raito@noreply.git.rz.ens.wtf> Co-committed-by: raito <raito@noreply.git.rz.ens.wtf>
13 lines
533 B
Nix
13 lines
533 B
Nix
let
|
|
pkgs = import <nixpkgs> {};
|
|
lib = pkgs.lib;
|
|
readPubkeys = user: builtins.filter (k: k != "") (lib.splitString "\n" (builtins.readFile (../pubkeys + "/${user}.keys")));
|
|
superadmins = (readPubkeys "raito") ++ (readPubkeys "gdd");
|
|
core-services-01 = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILrnZxP4OUGDzd1uykMghzFNLH0Fg42hH+0qxif6O6oU";
|
|
systems = [ core-services-01 ];
|
|
in
|
|
{
|
|
"keycloakDatabasePasswordFile.age".publicKeys = superadmins ++ systems;
|
|
"oauth2ProxyKeyFile.age".publicKeys = superadmins ++ systems;
|
|
}
|
|
|