aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--nix_path_env4
-rw-r--r--nixops/modules/ssh/default.nix4
2 files changed, 4 insertions, 4 deletions
diff --git a/nix_path_env b/nix_path_env
index 8e4c84d..bd976b6 100644
--- a/nix_path_env
+++ b/nix_path_env
@@ -4,9 +4,9 @@ if [ -z "$NIXOPS_DEPLOYMENT" ]; then
4 # This will automatically upgrade to latest version at each build 4 # This will automatically upgrade to latest version at each build
5 nixpkgs="https://nixos.org/channels/nixos-19.03/nixexprs.tar.xz" 5 nixpkgs="https://nixos.org/channels/nixos-19.03/nixexprs.tar.xz"
6else 6else
7 nixpkgs="https://releases.nixos.org/nixos/19.03/nixos-19.03beta171931.3a4ffdd38b5/nixexprs.tar.xz" 7 nixpkgs="https://releases.nixos.org/nixos/19.03/nixos-19.03.172361.cf3e277dd0b/nixexprs.tar.xz"
8fi 8fi
9nixpkgsPrevious="https://releases.nixos.org/nixos/19.03/nixos-19.03beta171931.3a4ffdd38b5/nixexprs.tar.xz" 9nixpkgsPrevious="$nixpkgs"
10nixpkgsNext="$nixpkgs" 10nixpkgsNext="$nixpkgs"
11export NIX_PATH="nixpkgs=$nixpkgs:nixpkgsNext=$nixpkgsNext:nixpkgsPrevious=$nixpkgsPrevious" 11export NIX_PATH="nixpkgs=$nixpkgs:nixpkgsNext=$nixpkgsNext:nixpkgsPrevious=$nixpkgsPrevious"
12 12
diff --git a/nixops/modules/ssh/default.nix b/nixops/modules/ssh/default.nix
index ece4b9f..81b7751 100644
--- a/nixops/modules/ssh/default.nix
+++ b/nixops/modules/ssh/default.nix
@@ -11,12 +11,12 @@
11 mySecrets.keys = [{ 11 mySecrets.keys = [{
12 dest = "ssh-ldap"; 12 dest = "ssh-ldap";
13 user = "nobody"; 13 user = "nobody";
14 group = "nobody"; 14 group = "nogroup";
15 permissions = "0400"; 15 permissions = "0400";
16 text = myconfig.env.sshd.ldap.password; 16 text = myconfig.env.sshd.ldap.password;
17 }]; 17 }];
18 system.activationScripts.sshd = '' 18 system.activationScripts.sshd = ''
19 install -Dm400 -o nobody -g nobody -T /var/secrets/ssh-ldap /etc/ssh/ldap_password 19 install -Dm400 -o nobody -g nogroup -T /var/secrets/ssh-ldap /etc/ssh/ldap_password
20 ''; 20 '';
21 # ssh is strict about parent directory having correct rights, don't 21 # ssh is strict about parent directory having correct rights, don't
22 # move it in the nix store. 22 # move it in the nix store.