non-writable secrets

This commit is contained in:
Casper V. Kristensen 2024-05-09 17:26:55 +02:00
parent 5bfc0b0c7d
commit 52690b3169
4 changed files with 6 additions and 6 deletions

View file

@ -93,14 +93,14 @@
age.secrets.wireguard-preshared-key-file = {
file = "${secrets}/secrets/wireguard-preshared-key-file.age";
mode = "640";
mode = "440";
owner = "root";
group = "systemd-network";
};
age.secrets.wireguard-private-key-file-alpha = {
file = "${secrets}/secrets/wireguard-private-key-file-alpha.age";
mode = "640";
mode = "440";
owner = "root";
group = "systemd-network";
};

View file

@ -6,7 +6,7 @@
age.secrets.caddy-auth-sigma = {
file = "${secrets}/secrets/caddy-auth-sigma.age";
mode = "600";
mode = "400";
owner = "caddy";
group = "caddy";
};

View file

@ -123,7 +123,7 @@
age.secrets.mail-hashed-password-file = {
file = "${secrets}/secrets/mail-hashed-password-file.age";
mode = "600";
mode = "400";
owner = "root";
group = "root";
};

View file

@ -174,14 +174,14 @@
age.secrets.wireguard-preshared-key-file = {
file = "${secrets}/secrets/wireguard-preshared-key-file.age";
mode = "640";
mode = "440";
owner = "root";
group = "systemd-network";
};
age.secrets.wireguard-private-key-file-sigma = {
file = "${secrets}/secrets/wireguard-private-key-file-sigma.age";
mode = "640";
mode = "440";
owner = "root";
group = "systemd-network";
};