From 273b694e4f536b13289a8b9e4b958557ae912c58 Mon Sep 17 00:00:00 2001 From: Giulio De Pasquale Date: Fri, 6 Dec 2024 21:11:16 +0000 Subject: [PATCH] feat(secrets): added host key for architect and rekeyed secrets --- hosts/pubkeys.nix | 5 ++++- secrets/matrix-synapse.age | Bin 1086 -> 1625 bytes secrets/secrets.nix | 3 +-- secrets/teslamate.age | 40 +++++++++++++++++++++++-------------- 4 files changed, 30 insertions(+), 18 deletions(-) diff --git a/hosts/pubkeys.nix b/hosts/pubkeys.nix index 934d2d1..61df9f6 100644 --- a/hosts/pubkeys.nix +++ b/hosts/pubkeys.nix @@ -1,4 +1,7 @@ -{ +rec { architect = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICu7rSsZ+d3BkppimNHJj8xL5jfl5RxMU0+Q5cue0LUu root@architect"; + architectHostKey = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDGLLAtRzLtCExHLhpsC+vH1nXcla3wibbMOFRCwXfXjtn2A9DjewHBwcbQbYQa6yuaEa3vmvUyrUtW6RUAiGSNhDMUPz7swr5tujgO/6ToPf0vKDDeOCwK5wqmNoUlDf7qzkxwCiI0dPYuCr7uGt00/ebSGfp+F1zmgC9MxuefYMdX5Q5I7HoHOYbBC9q9ue5mc0g+F8GnmD+Pd2pDDiHpCflT+iOzLJH0gCcW/0e5q7XYKGs09Cm/L1zroHIb14Borndu0Mby7x2FlnSeap5KXr9rkKVyr3amX0mksb4N0T36MMJwLYcrvE0S8utFdHEusoYEkP3fjSgsKKHKEgiZbqaeA0oZHddG49JNBsCLmmrN8T142t1fftP4NdFyKpcI9gYsbXhZf6bheV1wQ/cpv3KkLGG7JlZeORRAc4xgT33BHvVXTcWCE2EYcNmdscrMOEw3mcDESu7S14iXZgGIUgYISZ3GTZ5+mNB6OoEwxqK+eYzYMyDpNBxv6/LlEvc= root@architect"; macbook = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQC1we38/N+t8Ah5yrLof8QUwhrob7/VXFKIddaJeOVBLuDVnW7ljiAtdtEiL69D/DV4Ohmt5wMvkAAjfuHmim6FD9A6lzPbSU4KH9W2dcckszKbbI636kuDwem/xui6BW3wJa6P+0xW5ksygEAkzcK2PXuC2b4B9uwhuUdKahiGMKDxISG/WianqAe72cGMfNkYvion3Y1VsMLUdm48d2ABnxNpr7NI9B5iJ8dziOft9gpgfz13CCQRlReo75gk/4xI+vSNrQp7eR+wzJy2/dZg/T8jtyA9Q6jVxrxBpqQ1LNXkAKaJkGo9OabF6Wgpzp+YTAurL4nwR2NaJxwFuyoKvACQy0ai4jrS3206gC6JXZv8ktZMZrwUN+jPqCwfgh5qObFkAqKCxbp52ioDek2MQLdOvzQBX//DBhGEp5rzHGLZ3vhRIiiQiaof5sF5zWiYDW5mqezSPNxJPX/BrTP/Wbs/jpwTLBh3wytiia0S1WXQmya89bqzTPFiDWvTRA62EVKB/JaQtPQQOFAxWwg799DMycPeZ81xttZOyMtI/MZSddyqx2S8fWGwvToZQvuZ38mSIpFseLM1IkgabRIrAmat5SBNGGy9Dqa0eMEa7bwIY/4CMB1y6HMTnaoMXA6cnQfHMoB/zyTZ6oTXIeqeOyiZsK+RN0Mvahj8mXi7dw== giulio@giulio-X230"; + + groups.architect = [ architect architectHostKey ]; } diff --git a/secrets/matrix-synapse.age b/secrets/matrix-synapse.age index 2fb01b256ab023393dd66734fabac1c4a382ab05..be10aa63113f9a3b56dd0f2c16c5761376083caa 100644 GIT binary patch literal 1625 zcmXxj$?NoX0f6!Lq7bwdK~ZYqcc{hJ@H3N{ER#~iB$I6>nM{(&N_$8qdnU_#Gg&4S zk-jKe#pR$N=s_vG2=*X?py-RxL#+!GU&<@e7jcCmuf?Mv-46W=p3CR)lju6C4&c(9 zv%30B4HBeBq3h3HwQYJ0TK`IOys#c1MbgW|F#hJCeN9+Wv&-rq~ z=&zT!__a=63IV~tn zVqsT9+8f3;s*rsU)LYV=P{>P!&SsCcNmvX2AmySwPO7$6r!k;o)vYIbz7sYlQa>v3 z`FQXt(;sl)P`T?#gJWe7P{)x~>&=oBnrs6LIu^$`O2o~UEiVAJ{WVL%hlVS9_PCJ| zVf0a4->b*$NG>X-Q=qWHw=+i;h%8m-D24P*>#Ujsp6)CS?DtM>N{K_Y@TKLcMLJDh zf{C~=qha?fwtSI5y|-9W#FC?ELeZQ-=^G&c1>M$+XZ2Z|osQE?1xL;#cbC1!d6<}E ze$-H1r=N-tn?qg=o4swV*U?U^s^(0|4W0y(WX7tEZ$|~o_sB9zcz>)st$>7141rL8WQGM1j|pU0KXbV|ZhMNbH-g+#_B z?EA+l7tYGGuNZv}r0kU&`SRLr?IAj7-A#S{b2Tdl)9S;W!{?OJu%*y4o zVy0Xg0V9|6b{2%|>F8=YT>Cjh=W`&BEsSD%%g*-_W=c8e1Ew_KIA_P%g_nGHMdjWi zjZXo|fTgOs#}EUw!`21pp$-rA{$Oyc^BGwkj{$DZk>z2p9YwN3#SLqm+4)M2dV$o6 z>8!ZqR4=3kt%N~7Ef#hRsh;J$WQT zjo2!2>_(@E!O}MXG|4E3YaGuIh8_ZXK$;!E(jp1!d`nzxEocEXiE^uMfOXQ&8XY4C zYbEduYr{<*sSskRV|I#sVt4A^aYd?qGn*4imQcQ?9$AwKS`Jie_+U3cXDZf^D0@WA zX5&Ve(BW|iy1u@?LLEVyY7gK<`_1JgrKi*xv^@8@m?Vmk&^WL4mJaR|;!~cHu*f;VY z7cZ~wKC1bDyjnuLUmBnI(DhQkbA$QZtKW7$a?k$s{qyY~z53dh{`$V(LEz`rbN|1Z Ly%PL8z8$>{@ya={ literal 1086 zcmXxi%gfsY003|{MI}sRB6v~u9h4!VOVT7wBU8*fP18J@=6Or=>^n`;=1V;Yb2!mW zyeKF>2GhepP^SzLrcN*Nsnf#-K2Xu&aEKFMn<9cIe}BWzPohRN5Ar%IM~nG^MV>%w z1Zdp9RTOC>FZ?at@xny~3`dH|lNy)uqm=SZvT(I(JyQyE(2+4LTqn%Z2ggno(`u{8 zf~ulxq)Bg-K9aD3Zume73pl_`W4z`XY3U6yWp0a5AeEHH6a|7vxETP}Lxh;C=`1SsllewA$t;66FNADq^-wvX_%2Vzqgh4O_c3ng0eZFlbG z9nuZ3$w*~n*aygphx%0tx4lH{YD=vyP+NpSSy48HxZJoIMUT*Opd&L~HMSv~Q;m*4 ziHNk#Vg!;|KuqVBl`1$k#Ugd+a2Z%Io&e_<$~$5>UYYDVrwJj5*G$QE)DK=hVo3vuCm6A!D* zN~A@{H2`hV6tliDV1^D_mvg+C`$K}*Kn}QCM=W9t>9%WfItYntXxn3ZEqNkSaUqW( zY)nS11(dN}ASi;ZrmV-}vtqXKf(^~g=GzKr&P7*(4UyqY$K)mjUJ7V3qu6mWP3XP@ zH}e?;wD{EWvS}suG$rlxPLMS7ZW0DQIp9>v&1xiUJAyQhtGL)0ve@m1@)Ue{(Fm_V zI-KEoU76^LCQl%0n&p)aG#ZVq7Ceqia@n$@6)y=XK`Wbuk`?@_qs<*V9HR){wfj!0 zb=tszpKjM*f_^`E>ydYr^I`MigS(DCapTFy4yjY<(uw0gboZbCbMM<<@B4f9+S5C) zUy+VG7oYoRy6dys&gS%+nEKtZYxdozN6%L0AAbMXo$^mTd zhta>D-0kM}iF*&7yA15?`{TNQ-tb>Ob>%`s_}qTvhO=M3x928b`*H6rm%iUQ^vtg} zUqAom(UY(Kw*P|n&id$!k6$=a?b-d%;ZMH3XWw0)UT&RxMf>;z^9*%*a*ZxGFFf$! L7f;>s{LlXZ2$F|% diff --git a/secrets/secrets.nix b/secrets/secrets.nix index debf966..5cd11d0 100644 --- a/secrets/secrets.nix +++ b/secrets/secrets.nix @@ -2,8 +2,7 @@ let pubkeyModule = import ../hosts/pubkeys.nix; pubkeys = [ pubkeyModule.macbook - pubkeyModule.architect - ]; + ] ++ pubkeyModule.groups.architect; in { "matrix-synapse.age".publicKeys = pubkeys; diff --git a/secrets/teslamate.age b/secrets/teslamate.age index adca2e2..5137bba 100644 --- a/secrets/teslamate.age +++ b/secrets/teslamate.age @@ -1,17 +1,27 @@ age-encryption.org/v1 -> ssh-rsa QXZdow -CQT2aQTk+SisKOmvpn28iqBAzYGbT4H8bD5YnqK8OV31EvXGnw8GnFZPxlOJ4sYo -ZlFKML3piYXB4fw4VybsLbyfl71lACIUzt9zKWPb9Fv3P2Q0QDyQEglrGYbMB0vt -s+agyoKuxyCL8I8yIXl3zCCCFqqgKMz+e7M4PnBUTVTfas/rACQ6RJal4JvdCVAx -F7ifJMr48ZXEfCAWUoHvKH9qQiyWtyf7gsdQ9lyKaNNBDQuc0GipdvrHqT94Cute -rHbbsq3JBzhzf3sRTnDMsALcG557n0Hts+Ff8B4VBR12wV6ylczaNsxKQ3p/ncXm -XSx0enXTHhJtPLRPY8Mfk4q3lO/o0EyhfYnZ/wGIY9KDYmQGvzg4wiwALZjLgO8w -6E5EppVCfeeRwYrGXqsFrOoKPSh3sZZy7+++kNw0yy4G3MsNrwfSgpJXxXe4X1cd -LnW09yVbCElndURIWfUxRFqHesmY4fhgC/REZvuM6R+5XZ5MDDnoEtGjU09EKL/C -kskloulQrdMxptDQWcTZ5tZdqOB69+Z8h8gj5nYr0wlBF31ZpqRf+HHqN8vcjHmT -yqn6hdhTrwpMKTxBujw/7yXuSFRLmzs/rUCd4tpr5v574ZEw+z47jE2Oz/aLoWN2 -+yECxJlMEmnr3liObzAIfd7hpZutapPs+a56QZunyz0 --> ssh-ed25519 7eGqHw skaIFQqSC1U6pfuB+ogFfSUT1FaKFz4qkIWM7jqtrFw -J7s7ssWFINwmK3EylqMUD8DeRgrcbtzhLAh11jK8iUM ---- hfC8wfr2Rw0DKXorqLWMVfBbAH2435D/DkyCw46jwf0 - 2EdOW4{_6SD[Hxɀ!sN5!B/#cikƤ׵Zo+A""ND o ՙ^îV}Ө.j떓{Xo2u2,\("3߅g铵vw) \ No newline at end of file +IyHp/kqk6u/HazW25tlI9YykJ3AHySgPWFmQzIjh+BXyqo4qSKdNfQr1rIYFQGCJ +liIaMto8CWtbZUOiBXWtB/q3Z++Q0Qy8N1woYqVJ7gSlSbz1jKyDk2ZIrWCQ0CbT +zimI2gsdLEn5nkpV/NrkltH0/1aCW7HHzOo6UYp5YCQAwPO4eii636CYN9pFY8aD +wGuusZVsdEiP9+ETpxL8X0YDS6qWXAjrufEVSMmipxODGY9F9BncgrBXf6vNj4zv +/SudTaE4e1tfEQ8PjL+qE+aPMCVHITJsYWARiKIcUB4A2yLPxK4hEPuY+ikaV5nb +u2YBndS7RHA0c0xYAME1QZ2GOgFe995N+qgWM2pPmFhlFM7blzHLZPgNPQvQhaF1 +dwv5mRnRhtLF27GWjtcPL0AaX2qWoVgWmjI03HY4m2RAXr+kPhs4asIb10iL5Zz2 +I4GyupuX/yvds7ckTiVNc6HGPYgfN2re4ml0Lsgu+qMu6qkSSPwe4gdB8PRnlil4 +JZS/rKXzLlqHW1P5PQLLaSO9DtiRIitbvNuWbTHdUK5bjEu8mjVzjT/u4JwHip7j +MpuWsSKEN6I+0hCfYfEwAWD4h6oTF+ckrRUXWg/p+K6IXBx4txCVHEZXymdBwf8I +eedRo2unHui7oT512HMXqx6DIIAPg/7Jr2/MWX+J6F8 +-> ssh-ed25519 7eGqHw 9InUXz9Z8OvxNqVYckohNJYgFndSU5WH9VO9f4KnjhQ +lfE8tuSjZ5xJ19xzONy78dOzqZjqAk8RENdhBXoAXKY +-> ssh-rsa tO3rGg +t0P8ve/N9fxcBdIqmFajtIfQGTHXnwwaRRKJOoz/0PlH52Iat76P7IhdBipU9aJz +4lj2aFxYePD9Qz6+sLA4IibArW0Ej/XAehOwMiXU5NcD5ICcuc9dpBMekBzHTH6F +Z9fsz9ogKjBgfCulCDlf7XwQgXXx1+I2ar82y8Qix2esqO4fY4wXl7xQTONpKg0l +5Nethgwy6Xji2CBAsQDKm5xZ2FynUNWzk404pfDIkLvsU9NL53SHZwM8dzWiKxlq +g+uPlNYetfyFNWM1m018ev63adlrrBdzTwNBv+QTXF2fACarBxkqSPHLPrVn+DvM +mDPcXQJiORtMyOLJze2nt6ikZB/AqZWhGKFUpawI8MHx1HPlibG/cwKxLdmxexJz +Fk+EaGDeInyr7UflYjTQt2WlnaenittVwyIs08tqeJ/7mA/9uft6ThySIM/Cxsj0 +sa85Pa6AnZhl5dpT7CIU3n1ZJIgk+ZLniMfZQdGxTVvZ2eqWhXqRhj9go0Obmk5G + +--- fbeSdbhIc1G8BtYb99EUWMDa5Zgu2Pd1b2EL9mEs80Y +;g g1jԷb* g1R̅36 \ No newline at end of file