nix-config/.sops.yaml

Ignoring revisions in .git-blame-ignore-revs. Click here to bypass and see the normal blame view.

437 lines
11 KiB
YAML
Raw Permalink Normal View History

keys:
# The PGP keys in keys/
- &admins
2023-09-16 12:58:48 +02:00
- DD0998E6CDF294537FC604F991FA5E5BF9AA901C # 0xA
- A5EE826D645DBE35F9B0993358512AE87A69900F # astro
2024-04-10 00:10:28 +02:00
- 8F79E6CD6434700615867480D11A514F5095BFA8 # dennis
- 4F9F44A64CC2E438979329E1F122F05437696FCE # poelzi
- 91EBE87016391323642A6803B966009D57E69CC6 # revol-xut
2023-09-16 12:58:48 +02:00
- 53B26AEDC08246715E15504B236B6291555E8401 # sandro
- 4B12EFA69166CA8C23FC47E49CD3A46248B660CA # vv01f
- A4B0F5A80C2E2448A97BEC25BB829C4DECA6CCB9 # winzlieb
2023-09-16 13:17:35 +02:00
- &users
- A5EE826D645DBE35F9B0993358512AE87A69900F # astro
2024-04-10 00:10:28 +02:00
- 8F79E6CD6434700615867480D11A514F5095BFA8 # dennis
2023-09-16 13:17:35 +02:00
- 53B26AEDC08246715E15504B236B6291555E8401 # sandro
- 9580391316684474BFBD41EC3E8C55248C19AF2A # xyrill
- &polygon-snowflake age12aukzah0pt2rck52hwn08kezyxueqz2f49ld7hpyuzmu847vavdqkunn5c # polygon
# Generate AGE keys from SSH keys with:
# nix-shell -p ssh-to-age --run 'ssh some.serv.zentralwerk.org cat /etc/ssh/ssh_host_ed25519_key.pub | ssh-to-age'
- &activity-relay age1a8k72egc2vg4jn445wwcr0a68y9xu5ft68s2xwehugs5sjawpv4q5nnrmy
2024-01-28 00:18:40 +01:00
- &auth age1y7lxpxskqclwqluft2ct2c3u8weehus6t8evwk7cdnpakxzgcquspn827x
- &blogs age1lccjvj9z8de4hfrdeumm9eu7awef4d9jygv3w7zdash3fhv6e53quy53wz
2022-08-01 00:16:40 +02:00
- &broker age1dj0d0339f4law7qvuzcv2fs6sf8why63s3l8tja0f8vsj7wefcds9drvte
- &buzzrelay age1j2euh5qt4a7cvx0t93uj4n9t8y8tkv9h3nefszc6g2q7t7gvngxswhrve0
2022-09-07 20:10:38 +02:00
- &c3d2-web age18h6vmfduhmj28wxdgur8wugn7scm5vwvwkj5sr4f7nl0czr2zvaqscsdsv
2023-08-09 00:27:12 +02:00
- &caveman age13dl5qjzddaazmquf7zfecru5tr4ld8l8xd7xpmhaqqzmchpua4usswqykd
2024-01-25 23:25:31 +01:00
- &dacbert age1g2ewsxcu5uqlesaznp2qwlcz8w66pxh4qxkul8wu7x8g2hw83saqxynpyk
- &dn42 age1726t33dl7pv3xrxxlafj2sexh7c0jm8pza84yu6l3wpz3fw5dauqxlass3
2023-01-29 22:45:13 +01:00
- &drone age1w6u8zjfya63q9rjfll98eegnfdsvyaspnwn802t2mxh47gt8p30q0kn898
2022-09-11 04:12:39 +02:00
- &freifunk age17rrjtdgzzwgjatyqqv27pftx42t8xhksls46jc3f78juzw4g04vsd7lr7e
2022-09-07 20:10:38 +02:00
- &ftp age1lkr5rkf3z0976g8snmznf755gnexhjkwpzsw8xxwyesqmneawa4qgsqx77
- &gitea age12n5k6c4rxp4mjnexw9uw83yp34sallt44kldupfmxr2xkppj8a8sdsmv8h
2022-08-01 00:16:40 +02:00
- &glotzbert age1zqpep2vgfqeyvtj2jpxczfgrpjffwda429rnuztfp0vpqsrqdq8s8f4yua
2022-09-07 20:10:38 +02:00
- &gnunet age1kk0thtx6mg5cs0gqm4ylc4r8w6klq660s3j04w7m8w0w084yrpcqh3tqwf
- &grafana age1yahhqn2620300n20k68az5lr2u42wdgtjwysgqyr99a4cj52ay0qjw02pl
- &hedgedoc age1jt5pj0c0fvmzg7quaucq4n2rzcx9ajzstp8ruwc8ewjpay5vqfqsdjaal8
2023-04-07 01:42:21 +02:00
- &home-assistant age1l2tld2cttpkj4vpuh9hm4xjwq94rmf8vukjgvdzcvwwtze6k6s6qjf0s5r
- &hydra age1px8sjpcmnz27ayczzu883n0p5ad34vnzj6rl9y2eyye546v0m3dqfqx459
2022-09-07 20:10:38 +02:00
- &jabber age1tnq862ekxepjkes6efr282uj9gtcsqru04s5k0l2enq5djxyt5as0k0c2a
2024-01-28 00:18:40 +01:00
- &knot age1hfzpctkk5tz0ddc86ul9t0nf8c37jtngawepvgxk5rxlvv938vusx4kuc6
2024-04-12 20:37:42 +02:00
- &mail age15t7hj27j6ccs8u7mfz8su3aa74g4dxp4crkgc3c0rs28hct7q4ssgk8zcm
2022-11-30 01:17:39 +01:00
- &mastodon age1dcpd6u4psq3hehjyjrt3s7kzmnvxd20vsc8urjcdv6anr5v7ky2sq9rhtt
- &matemat age15vmz2evhnkn26fyt4vqvgztfrsr2s8qavd2m6zfjmkh84q2g75csnc5kr6
2023-03-24 01:55:57 +01:00
- &matrix age1s2ww76ll6nclz74gny27tk42xfsepl23z2k0849a8jv8xpnmpe3shgunxr
- &mediawiki age1xjvep7hsnfefgxvuwall8nq0486qu8yknhzwhf0cskw5xlpm8qws9txc56
- &mobilizon age182ms3ygypflk7mtpemp4k4ks9rz4gwhvzc9jlk95u4py5q68ppxstzu2e3
2024-04-15 16:08:14 +02:00
- &mucbot age1qen44cx5sx0y299zl93cz3tflx8agt8y9vtm0d4uxw42t9gyecdsw9jade
2022-09-07 20:10:38 +02:00
- &nfsroot age18yxgwpakrkzq8ca2enayf79py25se3d8dsed2q523869re30jcaqx6rjln
- &nncp age15853dr2kd6r2329tkcanwnruh6zd2xvsu5twc7gnxeyu3h7t6q5scckaq8
2022-08-01 00:16:40 +02:00
- &oparl age14aq8fscrwkgmu5yv86vj7p7kmxclzs6dp7fpvdhvrnmce83ztphqc4mr9q
2023-11-11 04:24:58 +01:00
- &owncast age1cp9gsuyfu52exk0hr3fvj404v5njhahakzwlugwtneyrs4vgdyaq0sg92f
- &pretalx age1u6xeayzwfdj9l0mg3f4xvjd8e9nemz5psqavauvacjgp2nku95yqc4f29s
2024-01-28 00:18:40 +01:00
- &prometheus age13xhxqulvswuckmpkmy2fgeqd5jx0ar8e2hst33leljt69r6hsvnsrdw63k
2022-09-07 20:10:38 +02:00
- &public-access-proxy age1xcj6peyaf5xvj2673vl9j0z7supwtw7hzuk782zk7gt69k2ykytqe65mg5
- &pulsebert age12hdk2stter0cjexxwx3sqn9wx3vmptkxszvx7knq9zgm9uqzjs7suvkcqu
2022-08-01 00:16:40 +02:00
- &radiobert age1lga6hjmxa95fmtdn3frlmy64ej3hyswxrcuz25qvw0kfsxkqeugs8gjw8q
2022-09-07 20:10:38 +02:00
- &riscbert age148d87gqw59lmst5jv3vynhsu3tv4t4sj49s4lktvnplfcrjq2y5sjcwsu8
- &scrape age1p60rg45qrzpv2hcfzxl8d8k9afkk7dtrhr98cngeyuhlega83ynssmtx5k
2022-09-07 20:10:38 +02:00
- &sdrweb age1makkpv2t74lxmw0nk6m89nespva7j700pmt83pl5a4ldtj2k8fzqakw8h7
2024-01-28 00:18:40 +01:00
- &server10 age15qj8latetnrmgzd7krq02y65kn7lhq2pcwv8cvzej2783u5a9scqs79nmf
2022-12-28 01:45:10 +01:00
- &server8 age12jcu0jtw7m96evxnd0vu6lvsm8uswslrdhxd2u655vjrwhljmqdsptry37
2022-09-07 20:10:38 +02:00
- &server9 age15vrlmtckjf4j242juw7l5e0s6eunn67ejr9acaztnl3tmvwpufrsevntva
- &spaceapi age125k9uyqw5ae5jqkfsak4d6c6rcx9q63ywuusk62pmxdnhwzqxgqq2jsau7
2022-08-01 00:16:40 +02:00
- &storage-ng age1qjvds58pedjdk9rj0yqfvad4xhpteapr9chvfucwcgwrsr8n7axqyhg2vu
2024-01-28 00:18:40 +01:00
- &stream age14h2npkt6m40ewkkaee7zx49redew5rjsjpm70qhka8cwkekmspqqpspy4g
2022-09-07 20:35:55 +02:00
- &ticker age1kdrpaqsy7gdnf80fpq6qrrc98nqjuzzlqx955uk2pkky3xcxky8sw9cdjl
- &vaultwarden age1xs22728ltpl3yh8hzvwt4g3gk8uc32lg8cqh86fp5d8c2jlvp3gshmejun
creation_rules:
- path_regex: modules/backup\.yaml$
key_groups:
- pgp: *admins
age:
- *activity-relay
2023-11-12 02:54:33 +01:00
- *auth
2023-06-05 21:37:55 +02:00
- *blogs
2023-05-19 14:52:54 +02:00
- *buzzrelay
2023-10-12 22:32:44 +02:00
- *caveman
2023-05-23 21:00:29 +02:00
- *drone
- *gitea
2023-11-14 01:38:25 +01:00
- *grafana
2023-05-18 18:36:16 +02:00
- *hedgedoc
2023-11-14 02:44:30 +01:00
- *home-assistant
- *hydra
2023-05-22 00:51:27 +02:00
- *jabber
2024-04-12 20:37:42 +02:00
- *mail
- *mastodon
- *matemat
2023-05-18 17:15:18 +02:00
- *matrix
- *mediawiki
- *mobilizon
2023-11-11 23:21:00 +01:00
- *owncast
- *pretalx
- *sdrweb
2023-05-18 17:15:18 +02:00
- *ticker
- *vaultwarden
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
2023-05-21 22:01:09 +02:00
- path_regex: modules/cluster/[^/]+\.yaml$
key_groups:
- pgp: *admins
age:
- *hydra
- *server8
- *server9
- *server10
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: config/[^/]+\.yaml$
key_groups:
- pgp: *admins
age:
- *polygon-snowflake
- *auth
- *blogs
- *broker
- *buzzrelay
2022-09-07 20:10:38 +02:00
- *c3d2-web
- *dacbert
- *dn42
- *freifunk
2022-09-07 20:10:38 +02:00
- *ftp
- *gitea
- *glotzbert
2022-09-07 20:10:38 +02:00
- *gnunet
- *grafana
- *hedgedoc
- *hydra
2022-09-07 20:10:38 +02:00
- *jabber
2024-01-28 00:18:40 +01:00
- *knot
2024-04-12 20:37:42 +02:00
- *mail
2022-11-30 01:17:39 +01:00
- *mastodon
- *matemat
2023-03-24 01:55:57 +01:00
- *matrix
- *mediawiki
- *mucbot
2022-09-07 20:10:38 +02:00
- *nfsroot
- *oparl
- *pretalx
2022-11-29 02:11:39 +01:00
- *prometheus
2022-09-07 20:10:38 +02:00
- *public-access-proxy
- *pulsebert
- *radiobert
2022-09-07 20:10:38 +02:00
- *riscbert
- *scrape
2022-09-07 20:10:38 +02:00
- *sdrweb
2023-01-07 02:54:35 +01:00
- *server8
2022-09-07 20:10:38 +02:00
- *server9
- *server10
- *spaceapi
- *storage-ng
2024-01-27 22:09:55 +01:00
- *stream
- *ticker
- *vaultwarden
2023-09-16 12:38:02 +02:00
- path_regex: hosts/activity-relay/secrets\.yaml$
key_groups:
- pgp: *admins
age:
- *activity-relay
- *polygon-snowflake
- path_regex: hosts/auth/secrets\.yaml$
key_groups:
- pgp: *admins
age:
2022-08-01 00:16:40 +02:00
- *auth
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
2024-01-28 00:18:40 +01:00
- path_regex: hosts/knot/secrets\.yaml$
2022-12-27 00:59:29 +01:00
key_groups:
- pgp: *admins
age:
2024-01-28 00:18:40 +01:00
- *knot
2022-12-27 00:59:29 +01:00
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/blogs/secrets\.yaml$
key_groups:
- pgp: *admins
age:
2022-08-01 00:16:40 +02:00
- *blogs
- *polygon-snowflake
2022-08-01 00:16:40 +02:00
- path_regex: hosts/broker/secrets\.yaml$
key_groups:
- pgp: *admins
age:
2022-08-01 00:16:40 +02:00
- *broker
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/buzzrelay/secrets\.yaml$
key_groups:
- pgp: *admins
age:
- *buzzrelay
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/c3d2-web/secrets\.yaml$
2022-12-26 23:14:54 +01:00
key_groups:
- pgp: *admins
age:
- *c3d2-web
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/caveman/secrets\.yaml$
2023-08-09 00:27:12 +02:00
key_groups:
- pgp: *admins
age:
- *caveman
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/dacbert/secrets\.yaml$
2023-01-29 22:45:13 +01:00
key_groups:
- pgp: *admins
age:
- *dacbert
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/dn42/secrets\.yaml$
key_groups:
- pgp: *admins
age:
- *dn42
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/drone/secrets\.yaml$
key_groups:
- pgp: *admins
age:
2023-01-29 22:45:13 +01:00
- *drone
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/freifunk/secrets\.yaml$
key_groups:
- pgp: *admins
age:
2022-08-01 00:16:40 +02:00
- *freifunk
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/gitea/secrets\.yaml$
2023-03-18 01:33:20 +01:00
key_groups:
- pgp: *admins
age:
- *gitea
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/glotzbert/secrets\.yaml$
key_groups:
- pgp: *admins
age:
2022-08-01 00:16:40 +02:00
- *glotzbert
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/grafana/secrets+\.yaml$
2022-10-27 21:35:39 +02:00
key_groups:
- pgp: *admins
age:
- *grafana
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/hedgedoc/secrets+\.yaml$
key_groups:
- pgp: *admins
age:
2022-08-01 00:16:40 +02:00
- *hedgedoc
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/home-assistant/secrets+\.yaml$
2023-04-07 01:42:21 +02:00
key_groups:
- pgp: *admins
age:
- *home-assistant
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/hydra/secrets\.yaml$
key_groups:
- pgp: *admins
age:
- *hydra
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/jabber/secrets\.yaml$
2022-12-27 00:06:49 +01:00
key_groups:
- pgp: *admins
age:
- *jabber
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
2024-04-12 20:37:42 +02:00
- path_regex: hosts/mail/secrets\.yaml$
key_groups:
- pgp: *admins
age:
2024-04-12 20:37:42 +02:00
- *mail
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/mastodon/secrets\.yaml$
2022-11-30 01:17:39 +01:00
key_groups:
- pgp: *admins
age:
- *mastodon
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/matemat/secrets\.yaml$
2022-12-26 23:18:02 +01:00
key_groups:
- pgp: *admins
age:
- *matemat
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/matrix/secrets\.yaml$
2023-03-24 01:55:57 +01:00
key_groups:
- pgp: *admins
age:
- *matrix
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/mediawiki/secrets\.yaml$
key_groups:
- pgp: *admins
age:
2022-08-01 00:16:40 +02:00
- *mediawiki
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/mobilizon/secrets\.yaml$
key_groups:
- pgp: *admins
age:
- *mobilizon
- *polygon-snowflake
2024-04-15 15:31:37 +02:00
- path_regex: hosts/mucbot/secrets\.yaml$
key_groups:
- pgp: *admins
age:
- *mucbot
- *polygon-snowflake
- path_regex: hosts/oparl/secrets\.yaml$
key_groups:
- pgp: *admins
age:
- *oparl
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
2023-11-11 04:24:58 +01:00
- path_regex: hosts/owncast/secrets\.yaml$
key_groups:
- pgp: *admins
age:
- *owncast
- *polygon-snowflake
- path_regex: hosts/pretalx/secrets\.yaml$
key_groups:
- pgp: *admins
age:
- *pretalx
- *polygon-snowflake
2023-12-12 00:50:48 +01:00
- path_regex: hosts/sdrweb/secrets\.yaml$
key_groups:
- pgp: *admins
age:
- *sdrweb
- *polygon-snowflake
- path_regex: hosts/radiobert/secrets\.yaml$
key_groups:
- pgp: *admins
age:
2022-08-01 00:16:40 +02:00
- *radiobert
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
2024-04-15 21:39:21 +02:00
- path_regex: hosts/scrape/secrets\.yaml$
key_groups:
- pgp: *admins
age:
- *scrape
- *polygon-snowflake
- path_regex: hosts/server8/secrets\.yaml$
2022-12-28 01:45:10 +01:00
key_groups:
- pgp: *admins
age:
- *server8
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/server9/secrets\.yaml$
2022-12-28 01:45:10 +01:00
key_groups:
- pgp: *admins
age:
- *server9
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/server10/secrets\.yaml$
2022-12-28 01:45:10 +01:00
key_groups:
- pgp: *admins
age:
- *server10
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/storage-ng/secrets\.yaml$
2022-08-01 00:16:40 +02:00
key_groups:
- pgp: *admins
age:
- *storage-ng
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/ticker/secrets\.yaml$
2023-05-18 17:15:18 +02:00
key_groups:
- pgp: *admins
age:
- *ticker
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/prometheus/secrets\.yaml$
2022-11-29 02:11:39 +01:00
key_groups:
- pgp: *admins
age:
- *prometheus
- *polygon-snowflake
2023-09-16 12:38:02 +02:00
- path_regex: hosts/stream/secrets\.yaml$
2023-06-08 01:28:14 +02:00
key_groups:
- pgp: *admins
age:
- *stream
- *polygon-snowflake
- path_regex: hosts/vaultwarden/secrets\.yaml$
key_groups:
- pgp: *admins
age:
- *vaultwarden
- *polygon-snowflake