Compare commits

...

2 commits

Author SHA1 Message Date
Jermeiah S
7d6059f302
prepare secrets 2025-06-14 21:39:36 -04:00
Jermeiah S
480334e081
remove firewall improve otf 2025-06-14 21:39:28 -04:00
2 changed files with 12 additions and 3 deletions

View file

@ -20,10 +20,19 @@ in
tty-ips.enable = true;
otf = {
enable = true;
environment = {
# OTF_KEY_FILE=/fixtures/key.pem
# SSL_CERT_FILE=/fixtures/cert.pem
# OTF_LOG_HTTP_REQUESTS = "true";
OTF_ADDRESS = "0.0.0.0:9000";
OTF_HOSTNAME = "tofu.skdevstudios.com";
OTF_DEFAULT_ENGINE = "tofu";
};
environmentFile = config.sops.secrets.otfenv.path;
};
};
networking = {
firewall.enable = false;
yggdrasil = {
enable = true;
AllowedPublicKeys = [

View file

@ -1,4 +1,4 @@
otfenv: ENC[AES256_GCM,data:HwZC2IPM9w5FqFlpc/zLA+m9bSC6m19hnvuS103Iwct84QM/HHkez3pdLdCZM5tNZN+oItxMHcIizbcA7mQn1eezdt+Pb9RC4hk=,iv:rcvPhmVEg79XPpJ6o8/DBP4YgN+lgjvxLB1mJYARdCo=,tag:SSZiiKngO+vWjcEppnhARg==,type:str]
otfenv: ENC[AES256_GCM,data:6U17snf39rdW+plm03gVmGmFg5YJsyFYbr/cyqcSyWXA6B4A1SJtJiYhGU3dnXDTFmyvcY4NIW66m3/bMCnEQ2GEbl4XurR/+//cbCUwjidI/uyVVwLxa5KoukyFJou0iRKHfyRxIxFx42jDXL8I5seg8H9tJvIB6LU=,iv:nwV1iYFr949CcNJnEFo/3yvz2+p+P/KwXdZ4MJ5Yggw=,tag:kDOVp+jvIjcpCw3IoVfVyA==,type:str]
sops:
age:
- recipient: age1ja6zky2xlptgmu04ghp30z9gcyw240p4p8jpqeznt9msmmrwjdjshl6rx3
@ -28,7 +28,7 @@ sops:
Q3E1Y1pOR0NjN1M3RXFueU1YUzdZNm8KvmAh6XclVmdX2hDtRbBuYRF4mSCrIjJ6
P6JYyzB+aZXkbRiw0L7KoHOuQ1LyV0m3LOANcqpUn6phh0CNWxOmlg==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2025-06-14T18:56:57Z"
mac: ENC[AES256_GCM,data:oPKok5QCr8edihXzZUZl3+5Abss6OMas4rYqQZWeLkkIX+b3uzCi0p6KJsZK1SyxZC48Wa4ax8cGLb1BOIQVCjyR80OkXDzQACee9War2LVceXcoT1ARqgl21nthmckLxYzs+YOxWbB3gFQNOD09aeenLpSJUzMM7kDV901sCVg=,iv:ywJaJYj2xrNkgQsWZJF51ZUAwBwMk14eQDe9EC6EXaQ=,tag:GQlHIofanq/yETLbAqS2Nw==,type:str]
lastmodified: "2025-06-15T01:38:41Z"
mac: ENC[AES256_GCM,data:QgsUJQr8SjTYJDNkrrYoqqh34fZQMebIgL9g1BtXeCAT/vA32TABCx4SYDfZ0Ws7gDAv0dfnqY8csRVFySw3qiNCHme15JxIFOy0b4j0zV3hqkcX8GIZ2PwNHMm1Y1Hze/y7kqD0XoYSa+BJROht1uU8c5eArHU9KpTxiMSNGpk=,iv:e1ICn+xa+rNftRBFa6zNijFKpQEzXclhHISGuIVOP3M=,tag:03HWccVS7XzSk0vZPk+kYA==,type:str]
unencrypted_suffix: _unencrypted
version: 3.10.2