diff --git a/flake.lock b/flake.lock index 7293506..b01a5af 100644 --- a/flake.lock +++ b/flake.lock @@ -1529,11 +1529,11 @@ ] }, "locked": { - "lastModified": 1783460601, - "narHash": "sha256-Fxxxb2+aajzdCEZxkQvtRoDVbA4UAOMm++lWhkF15uA=", + "lastModified": 1783478296, + "narHash": "sha256-Ye66G3O7LCbffDtOsWela85w6m9SyKK/d0eT+EpzoHg=", "owner": "nix-community", "repo": "NUR", - "rev": "7b8544afc53e3c26658482ec0b98d0113d7cdeb8", + "rev": "ee50cde4c59d24b446f4af344e4fda4e1ddbd1ab", "type": "github" }, "original": { diff --git a/modules/nix/default.nix b/modules/nix/default.nix index 66565ed..dc41450 100644 --- a/modules/nix/default.nix +++ b/modules/nix/default.nix @@ -10,14 +10,27 @@ in { sops = { secrets."nix_access_tokens/github" = {}; - secrets."nix_access_tokens/ncps" = {}; - templates.access_tokens = { - content = let - ncpsHost = "ncps.${vars.groundDomain}"; - in '' - access-tokens = github.com=${config.sops.placeholder."nix_access_tokens/github"} ${ncpsHost}=${config.sops.placeholder."nix_access_tokens/ncps"} - ''; - owner = username; + + templates = { + access_tokens = { + content = '' + access-tokens = github.com=${config.sops.placeholder."nix_access_tokens/github"} + ''; + owner = username; + }; + + nix-netrc = { + content = let + ncpsHost = "ncps.${vars.groundDomain}"; + in '' + machine ${ncpsHost} + login nix + password ${config.sops.placeholder."nix_access_tokens/ncps"} + ''; + group = "root"; + mode = "0400"; + owner = "root"; + }; }; }; @@ -33,10 +46,8 @@ # keep-sorted end ]; in { - # Add binary caches. inherit substituters; - # Allow trusted users to opt into the same caches from per-user config. trusted-substituters = substituters; trusted-public-keys = [ @@ -50,6 +61,8 @@ # keep-sorted end ]; + netrc-file = config.sops.templates.nix-netrc.path; + experimental-features = [ # keep-sorted start "flakes" @@ -66,7 +79,7 @@ }; # Load access tokens from the generated sops template. - extraOptions = "!include ${config.sops.templates."access_tokens".path}"; + extraOptions = "!include ${config.sops.templates.access_tokens.path}"; }; nixpkgs.config = {