From c1ba07fb0ad7e1d4e306ec98c30dc4274e4e997c Mon Sep 17 00:00:00 2001 From: Adam0 Date: Fri, 29 May 2026 00:17:26 +0200 Subject: [PATCH] remove secrets repo --- .gitignore | 1 + README.md | 6 +++--- flake.lock | 17 ----------------- flake.nix | 4 ---- modules/nix/sops.nix | 16 ++++++++-------- 5 files changed, 12 insertions(+), 32 deletions(-) diff --git a/.gitignore b/.gitignore index 582ee4e..4c9ee5c 100644 --- a/.gitignore +++ b/.gitignore @@ -2,4 +2,5 @@ .direnv .rumdl_cache result* +secrets.yaml # keep-sorted end diff --git a/README.md b/README.md index eb8928f..beb5187 100644 --- a/README.md +++ b/README.md @@ -60,14 +60,14 @@ nix run .#write-flake ## Secrets -- Runtime secrets are kept outside this public repo in the private `adam01110/secrets` flake input. +- Runtime secrets live in a local `secrets.yml` at the project root (gitignored). - Recipient rules live in `.sops.yaml` for one user PGP key and three host Age keys. - SOPS Nix is shared between NixOS and Home Manager through `modules/nix/sops.nix`. -Edit flow for the private secrets repository: +Edit flow: ```bash -sops secrets.yaml +sops secrets.yml ``` ## Customization diff --git a/flake.lock b/flake.lock index 19e6c3e..bd62c5a 100644 --- a/flake.lock +++ b/flake.lock @@ -1651,7 +1651,6 @@ "nur": "nur", "nvf": "nvf", "overzicht": "overzicht", - "secrets": "secrets", "sops-nix": "sops-nix", "spicetify-nix": "spicetify-nix", "stylix": "stylix", @@ -1702,22 +1701,6 @@ "type": "github" } }, - "secrets": { - "flake": false, - "locked": { - "lastModified": 1779478615, - "narHash": "sha256-AdsgPi/RA9eQWQFCn3iNyRoUzlkRfOkMsd6ndoRsUtk=", - "ref": "refs/heads/main", - "rev": "bf2aad377f3cf16f87172760b8e24f05011667de", - "revCount": 2, - "type": "git", - "url": "ssh://git@github.com/adam01110/secrets.git" - }, - "original": { - "type": "git", - "url": "ssh://git@github.com/adam01110/secrets.git" - } - }, "sops-nix": { "inputs": { "nixpkgs": [ diff --git a/flake.nix b/flake.nix index cb2dbc7..0fbc6f5 100644 --- a/flake.nix +++ b/flake.nix @@ -102,10 +102,6 @@ treefmt-nix.follows = "treefmt-nix"; }; }; - secrets = { - url = "git+ssh://git@github.com/adam01110/secrets.git"; - flake = false; - }; sops-nix = { url = "github:Mic92/sops-nix"; inputs.nixpkgs.follows = "nixpkgs"; diff --git a/modules/nix/sops.nix b/modules/nix/sops.nix index c735d9a..93dd1ba 100644 --- a/modules/nix/sops.nix +++ b/modules/nix/sops.nix @@ -1,7 +1,12 @@ -{inputs, ...}: let +{ + # keep-sorted start + inputs, + self, + # keep-sorted end + ... +}: let sopsConfig = { - # Keep the shared secret inventory outside the public infra repo. - defaultSopsFile = "${inputs.secrets}/secrets.yaml"; + defaultSopsFile = "${self}/secrets.yml"; defaultSopsFormat = "yaml"; validateSopsFiles = false; @@ -15,11 +20,6 @@ }; in { flake-file.inputs = { - secrets = { - url = "git+ssh://git@github.com/adam01110/secrets.git"; - flake = false; - }; - sops-nix = { url = "github:Mic92/sops-nix"; inputs.nixpkgs.follows = "nixpkgs"; -- 2.51.2