pdr: secrets??

This commit is contained in:
41666 2024-03-29 21:50:46 -04:00
parent 9277d55791
commit b57795bead

View file

@ -18,13 +18,26 @@
mode = "0444";
};
sops.templates."secrets.yaml" = {
content = lib.generators.toYAML {
db = {
pass = config.sops.placeholder.db_password;
};
};
owner = config.services.iceshrimp.user;
group = config.services.iceshrimp.group;
};
services.iceshrimp = {
enable = true;
settings.url = "https://porcelain.doll.repair";
dbPasswordFile = config.sops.secrets.db_password.path;
createDb = true;
configureNginx.enable = false;
secretConfig = config.sops.templates."secrets.yaml".path;
};
services.postgresql.package = pkgs.postgresql_15;
services.redis.servers.iceshrimp.logfile = "stdout";
}