]> git.immae.eu Git - perso/Immae/Config/Nix.git/blobdiff - nixops/modules/ssh/default.nix
Move ssh ftp and mpd to new secrets
[perso/Immae/Config/Nix.git] / nixops / modules / ssh / default.nix
index 924f86e213427d18f9e16cc9298ebab2a1002c7f..ece4b9ff7518293967ca713d31953dba0c45c244 100644 (file)
@@ -8,16 +8,15 @@
       AuthorizedKeysCommandUser nobody
       '';
 
-    deployment.keys = {
-      ssh-ldap = {
-        user = "nobody";
-        group = "nobody";
-        permissions = "0400";
-        text = myconfig.env.sshd.ldap.password;
-      };
-    };
+    mySecrets.keys = [{
+      dest = "ssh-ldap";
+      user = "nobody";
+      group = "nobody";
+      permissions = "0400";
+      text = myconfig.env.sshd.ldap.password;
+    }];
     system.activationScripts.sshd = ''
-      install -Dm400 -o nobody -g nobody -T /run/keys/ssh-ldap /etc/ssh/ldap_password
+      install -Dm400 -o nobody -g nobody -T /var/secrets/ssh-ldap /etc/ssh/ldap_password
       '';
     # ssh is strict about parent directory having correct rights, don't
     # move it in the nix store.