sops instructions
This commit is contained in:
@@ -7,7 +7,6 @@
|
||||
caPort = 443;
|
||||
|
||||
caPasswordPath = (lib.getAttr cfg.secrets.caPassword config.sops.secrets).path;
|
||||
intermediateCrtPath = (lib.getAttr cfg.secrets.intermediateCrt config.sops.secrets).path;
|
||||
intermediateKeyPath = (lib.getAttr cfg.secrets.intermediateKey config.sops.secrets).path;
|
||||
sshHostCaKeyPath = (lib.getAttr cfg.secrets.sshHostCaKey config.sops.secrets).path;
|
||||
sshUserCaKeyPath = (lib.getAttr cfg.secrets.sshUserCaKey config.sops.secrets).path;
|
||||
@@ -16,7 +15,7 @@
|
||||
|
||||
renderedStepCaConfig = builtins.toJSON {
|
||||
root = cfg.rootCertPath;
|
||||
crt = intermediateCrtPath;
|
||||
crt = cfg.intermediateCertPath;
|
||||
key = intermediateKeyPath;
|
||||
address = "${caAddress}:${toString caPort}";
|
||||
dnsNames = cfg.dnsNames;
|
||||
@@ -87,6 +86,10 @@
|
||||
description = "Path to the Step CA root certificate served by this host.";
|
||||
type = lib.types.path;
|
||||
};
|
||||
intermediateCertPath = lib.mkOption {
|
||||
description = "Path to the Step CA intermediate certificate served by this host. This is public material and does not need to be stored in SOPS.";
|
||||
type = lib.types.path;
|
||||
};
|
||||
dnsNames = lib.mkOption {
|
||||
description = "DNS names and IP SANs advertised by this Step CA instance.";
|
||||
type = with lib.types; listOf str;
|
||||
@@ -100,10 +103,6 @@
|
||||
description = "SOPS key for the Step CA intermediate password.";
|
||||
type = lib.types.str;
|
||||
};
|
||||
intermediateCrt = lib.mkOption {
|
||||
description = "SOPS key for the Step CA intermediate certificate.";
|
||||
type = lib.types.str;
|
||||
};
|
||||
intermediateKey = lib.mkOption {
|
||||
description = "SOPS key for the Step CA intermediate private key.";
|
||||
type = lib.types.str;
|
||||
@@ -132,13 +131,6 @@
|
||||
mode = "0400";
|
||||
restartUnits = [ "step-ca.service" ];
|
||||
};
|
||||
sops.secrets."${cfg.secrets.intermediateCrt}" = {
|
||||
sopsFile = cfg.secrets.sopsFile;
|
||||
owner = "step-ca";
|
||||
group = "step-ca";
|
||||
mode = "0400";
|
||||
restartUnits = [ "step-ca.service" ];
|
||||
};
|
||||
sops.secrets."${cfg.secrets.intermediateKey}" = {
|
||||
sopsFile = cfg.secrets.sopsFile;
|
||||
owner = "step-ca";
|
||||
@@ -184,7 +176,6 @@
|
||||
intermediatePasswordFile = caPasswordPath;
|
||||
};
|
||||
|
||||
# Keep modules/services/step-ca/ca.json as reference-only; runtime config comes from SOPS template.
|
||||
environment.etc."smallstep/ca.json".source =
|
||||
lib.mkForce config.sops.templates."step-ca-config".path;
|
||||
systemd.services.step-ca.restartTriggers =
|
||||
|
||||
Reference in New Issue
Block a user