preparing k3s bootstrapping

This commit is contained in:
Jakub Kropáček 2025-01-10 23:23:20 +01:00
parent cfe20fe39b
commit f4cd66b8d9
4 changed files with 14 additions and 2 deletions

View file

@ -29,7 +29,7 @@ in
} }
]; ];
age.secrets.k3stoken.file = ../../secrets/k3stoken.age; age.secrets.k3stoken.file = ../../../secrets/k3stoken.age;
services.k3s = { services.k3s = {
enable = true; enable = true;

7
secrets/k3stoken.age Normal file
View file

@ -0,0 +1,7 @@
age-encryption.org/v1
-> ssh-ed25519 5k28aQ wUKJk8gcxcCqbdXsfuod3dvEtj+pXRe8rLYVv/uyND4
aHOXSUwP5+AJZ5etU+dj9ssVNQNcDuXSpq+wvIYsoyE
-> ssh-ed25519 MhDGlw Ln5f8TTQFDlp+KGQpRRPNgn/+fzoY7Bnl7FlDg5ZSSs
uJbxZFjjcSxhIPHvregG1tD8BKKfHHMlvfZ6itDIppY
--- MGApTU7O6xSlpanV9LC22ZX2u7bwULpBMaTLg01SO/0
šâYøï ö¯J#<23>ž6/ó— 6 ñwTF¯ì fŒÔ¶¡ x×<78>º™5·Îÿ¸^

View file

@ -11,6 +11,10 @@
"hosts:wenar-nix", "hosts:wenar-nix",
"hosts:lenar", "hosts:lenar",
"servers:test-server" "servers:test-server"
],
"k3stoken.age": [
"hosts:wenar-nix",
"hosts:lenar"
] ]
} }
} }

View file

@ -9,4 +9,5 @@ let
in in
{ {
"mypassword.age".publicKeys = getKeys "mypassword.age"; "mypassword.age".publicKeys = getKeys "mypassword.age";
"k3stoken.age".publicKeys = getKeys "k3stoken.age";
} }