tvl-depot/ops/secrets/secrets.nix
Vincent Ambo 6b3eed1fb5 feat(ops/secrets): Add journaldriver key
This changes the structure of secrets.nix a bit to split between
secrets for whitby, and secrets for all TVL machines.

Change-Id: I791f0ce42a16b33051e24a7a6c5b153761ed9eb3
Reviewed-on: https://cl.tvl.fyi/c/depot/+/5300
Reviewed-by: sterni <sternenseemann@systemli.org>
Tested-by: BuildkiteCI
Autosubmit: tazjin <tazjin@tvl.su>
2022-02-17 18:11:58 +00:00

42 lines
1.4 KiB
Nix

let
tazjin = [
# tverskoy
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIM1fGWz/gsq+ZeZXjvUrV+pBlanw1c3zJ9kLTax9FWQy"
];
grfn = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMcBGBoWd5pPIIQQP52rcFOQN3wAY0J/+K2fuU6SffjA "
];
sterni = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJk+KvgvI2oJTppMASNUfMcMkA2G5ZNt+HnWDzaXKLlo"
];
sanduny = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOag0XhylaTVhmT6HB8EN2Fv5Ymrc4ZfypOXONUkykTX";
whitby = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILNh/w4BSKov0jdz3gKBc98tpoLta5bb87fQXWBhAl2I";
whitbyDefault.publicKeys = tazjin ++ grfn ++ sterni ++ [ whitby ];
allDefault.publicKeys = tazjin ++ grfn ++ sterni ++ [ sanduny whitby ];
in
{
"besadii.age" = whitbyDefault;
"buildkite-agent-token.age" = whitbyDefault;
"buildkite-graphql-token.age" = whitbyDefault;
"clbot-ssh.age" = whitbyDefault;
"clbot.age" = whitbyDefault;
"gerrit-queue.age" = whitbyDefault;
"gerrit-secrets.age" = whitbyDefault;
"grafana.age" = whitbyDefault;
"irccat.age" = whitbyDefault;
"journaldriver.age" = allDefault;
"keycloak-db.age" = whitbyDefault;
"nix-cache-priv.age" = whitbyDefault;
"nix-cache-pub.age" = whitbyDefault;
"oauth2_proxy.age" = whitbyDefault;
"owothia.age" = whitbyDefault;
"panettone.age" = whitbyDefault;
"smtprelay.age" = whitbyDefault;
"tf-glesys.age" = whitbyDefault;
"tf-keycloak.age" = whitbyDefault;
"tvl-alerts-bot-telegram-token.age" = whitbyDefault;
}