non-writable secrets
This commit is contained in:
parent
5bfc0b0c7d
commit
52690b3169
|
@ -93,14 +93,14 @@
|
||||||
|
|
||||||
age.secrets.wireguard-preshared-key-file = {
|
age.secrets.wireguard-preshared-key-file = {
|
||||||
file = "${secrets}/secrets/wireguard-preshared-key-file.age";
|
file = "${secrets}/secrets/wireguard-preshared-key-file.age";
|
||||||
mode = "640";
|
mode = "440";
|
||||||
owner = "root";
|
owner = "root";
|
||||||
group = "systemd-network";
|
group = "systemd-network";
|
||||||
};
|
};
|
||||||
|
|
||||||
age.secrets.wireguard-private-key-file-alpha = {
|
age.secrets.wireguard-private-key-file-alpha = {
|
||||||
file = "${secrets}/secrets/wireguard-private-key-file-alpha.age";
|
file = "${secrets}/secrets/wireguard-private-key-file-alpha.age";
|
||||||
mode = "640";
|
mode = "440";
|
||||||
owner = "root";
|
owner = "root";
|
||||||
group = "systemd-network";
|
group = "systemd-network";
|
||||||
};
|
};
|
||||||
|
|
|
@ -6,7 +6,7 @@
|
||||||
|
|
||||||
age.secrets.caddy-auth-sigma = {
|
age.secrets.caddy-auth-sigma = {
|
||||||
file = "${secrets}/secrets/caddy-auth-sigma.age";
|
file = "${secrets}/secrets/caddy-auth-sigma.age";
|
||||||
mode = "600";
|
mode = "400";
|
||||||
owner = "caddy";
|
owner = "caddy";
|
||||||
group = "caddy";
|
group = "caddy";
|
||||||
};
|
};
|
||||||
|
|
|
@ -123,7 +123,7 @@
|
||||||
|
|
||||||
age.secrets.mail-hashed-password-file = {
|
age.secrets.mail-hashed-password-file = {
|
||||||
file = "${secrets}/secrets/mail-hashed-password-file.age";
|
file = "${secrets}/secrets/mail-hashed-password-file.age";
|
||||||
mode = "600";
|
mode = "400";
|
||||||
owner = "root";
|
owner = "root";
|
||||||
group = "root";
|
group = "root";
|
||||||
};
|
};
|
||||||
|
|
|
@ -174,14 +174,14 @@
|
||||||
|
|
||||||
age.secrets.wireguard-preshared-key-file = {
|
age.secrets.wireguard-preshared-key-file = {
|
||||||
file = "${secrets}/secrets/wireguard-preshared-key-file.age";
|
file = "${secrets}/secrets/wireguard-preshared-key-file.age";
|
||||||
mode = "640";
|
mode = "440";
|
||||||
owner = "root";
|
owner = "root";
|
||||||
group = "systemd-network";
|
group = "systemd-network";
|
||||||
};
|
};
|
||||||
|
|
||||||
age.secrets.wireguard-private-key-file-sigma = {
|
age.secrets.wireguard-private-key-file-sigma = {
|
||||||
file = "${secrets}/secrets/wireguard-private-key-file-sigma.age";
|
file = "${secrets}/secrets/wireguard-private-key-file-sigma.age";
|
||||||
mode = "640";
|
mode = "440";
|
||||||
owner = "root";
|
owner = "root";
|
||||||
group = "systemd-network";
|
group = "systemd-network";
|
||||||
};
|
};
|
||||||
|
|
Loading…
Reference in a new issue