};
config = lib.mkIf cfg.enable {
- secrets.keys = [
- {
- dest = "zrepl/zrepl.yml";
+ secrets.keys = {
+ "zrepl/zrepl.yml" = {
permissions = "0400";
text = cfg.config;
user = config.systemd.services.zrepl.serviceConfig.User or "root";
group = config.systemd.services.zrepl.serviceConfig.Group or "root";
- }
- ];
+ };
+ };
services.filesWatcher.zrepl = {
restart = true;
paths = [ config.secrets.fullPaths."zrepl/zrepl.yml" ];