From f00cc9d6231ee41f72abffd559f120d66e6bbe07 Mon Sep 17 00:00:00 2001 From: Andrea Ciceri Date: Sat, 1 Apr 2023 15:37:52 +0200 Subject: [PATCH] Secrets rekeyed --- secrets/default.nix | 25 +++++----- secrets/git-workspace-tokens.age | Bin 1172 -> 1898 bytes secrets/magit-forge-github-token.age | 49 ++++++++++++------- secrets/mothership-wireguard-private-key.age | 9 ---- secrets/thinkpad-wireguard-private-key.age | 8 --- 5 files changed, 46 insertions(+), 45 deletions(-) delete mode 100644 secrets/mothership-wireguard-private-key.age delete mode 100644 secrets/thinkpad-wireguard-private-key.age diff --git a/secrets/default.nix b/secrets/default.nix index 1c85c41..6dbfb5e 100644 --- a/secrets/default.nix +++ b/secrets/default.nix @@ -1,17 +1,20 @@ let - users.ccr = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQC5cEUx25pnZiH3eBrE2xNbJ92gJiKSznDUNRzcEL4ti6FlJm+75p4q0hgdqHwStR8+uCWBL6viVFCGutOVMFE5MX1Oc3A8fJdR6H9Rrwvk/1UQzqzc9tWxw1qPLKz+fnPDomjOvNofghCWQRwX3Xf1HnIqvRwELpNbR9i+/cHkDGzLJxkstbt4gol8ywMPkw02QdKk8s5MEd1vawxc+7Chs0JPW57RDqDYFErYys52JLeAViCBB9bofF+KT42LuRXKSjWlvCV9kR5TL49vUeBgzMQWMh++WQdN4m9lpqFqYyc75I49/E0HGf8LChDSS+hvRnb5MbtnVGjEA4WDHyldmJCvUNob5CUo4FjoSPRi+S/J3Ads8D4JVwaJOJEVqmMKEhiQ0Hzk4hwe3eV/VumlZj4U/QjaCrqqi4TW/iP0gNRfzcfiM+G/z5R7w1NMUpTX7oilyKjMQmGnXB857D3SSptS7dwh5OiKhVmrQMRCduooUsj236abqLU28K//RnxhOgh8kDGgoUHApnTiMZNKhgLiR42lKrubNcW1tAAqoNyFLMwwXeMLjh0iP1b5y8ntfNPNIcGb7vcwpS24z/aIjW7rQ4J7x5EBphHGhys6ne+irdhOM8c7kFr+c8+Q2oU0YAtFuMYztAFOHm1e20X00Zvys2nuee+hT9F1NungAQ=="; + users = { + ccr-gpg = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQC5cEUx25pnZiH3eBrE2xNbJ92gJiKSznDUNRzcEL4ti6FlJm+75p4q0hgdqHwStR8+uCWBL6viVFCGutOVMFE5MX1Oc3A8fJdR6H9Rrwvk/1UQzqzc9tWxw1qPLKz+fnPDomjOvNofghCWQRwX3Xf1HnIqvRwELpNbR9i+/cHkDGzLJxkstbt4gol8ywMPkw02QdKk8s5MEd1vawxc+7Chs0JPW57RDqDYFErYys52JLeAViCBB9bofF+KT42LuRXKSjWlvCV9kR5TL49vUeBgzMQWMh++WQdN4m9lpqFqYyc75I49/E0HGf8LChDSS+hvRnb5MbtnVGjEA4WDHyldmJCvUNob5CUo4FjoSPRi+S/J3Ads8D4JVwaJOJEVqmMKEhiQ0Hzk4hwe3eV/VumlZj4U/QjaCrqqi4TW/iP0gNRfzcfiM+G/z5R7w1NMUpTX7oilyKjMQmGnXB857D3SSptS7dwh5OiKhVmrQMRCduooUsj236abqLU28K//RnxhOgh8kDGgoUHApnTiMZNKhgLiR42lKrubNcW1tAAqoNyFLMwwXeMLjh0iP1b5y8ntfNPNIcGb7vcwpS24z/aIjW7rQ4J7x5EBphHGhys6ne+irdhOM8c7kFr+c8+Q2oU0YAtFuMYztAFOHm1e20X00Zvys2nuee+hT9F1NungAQ== andrea.ciceri@autistici.org"; + ccr-ssh = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCzCmDCtlGscpesHuoiruVWD2IjYEFtaIl9Y2JZGiOAyf3V17KPx0MikcknfmxSHi399SxppiaXQHxo/1wjGxXkXNTTv6h1fBuqwhJE6C8+ZSV+gal81vEnXX+/9w2FQqtVgnG2/mO7oJ0e3FY+6kFpOsGEhYexoGt/UxIpAZoqIN+CWNhJIASUkneaZWtgwiL8Afb59kJQ2E7WbBu+PjYZ/s5lhPobhlkz6s8rkhItvYdiSHT0DPDKvp1oEbxsxd4E4cjJFbahyS8b089NJd9gF5gs0b74H/2lUUymnl63cV37Mp4iXB4rtE69MbjqsGEBKTPumLualmc8pOGBHqWIdhAqGdZQeBajcb6VK0E3hcU0wBB+GJgm7KUzlAHGdC3azY0KlHMrLaZN0pBrgCVR6zBNWtZz2B2qMBZ8Cw+K4vut8GuspdXZscID10U578GxQvJAB9CdxNUtrzSmKX2UtZPB1udWjjIAlejzba4MG73uXgQEdv0NcuHNwaLuCWxTUT5QQF18IwlJ23Mg8aPK8ojUW5A+kGHAu9wtgZVcX1nS5cmYKSgLzcP1LA1l9fTJ1vqBSuy38GTdUzfzz7AbnkRfGPj2ALDgyx17Rc5ommjc1k0gFoeIqiLaxEs5FzDcRyo7YvZXPsGeIqNCYwQWw3+U+yUEJby8bxGb2d/6YQ== andrea.ciceri@autistici.org"; + }; hosts = { - test = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHc46mGCuaKLwNzK/abuedYQLw9h/Cp5MhVb7IHTGh0E root@test"; thinkpad = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDZMyLFfuBeDfPLn8WL6JazYpYq3oVvCdD4ktyt915TL"; mothership = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFlepPWHE9GvQIBcAQBQPd80oiePSPxGDnMdqpdEqx6I"; }; -in { - "cachix.age".publicKeys = [users.ccr hosts.mothership]; - "autistici-password.age".publicKeys = [users.ccr]; - "magit-forge-github-token.age".publicKeys = [users.ccr hosts.mothership]; - "git-workspace-tokens.age".publicKeys = [users.ccr hosts.test hosts.mothership]; +in + with hosts; + with users; { + "cachix-personal-token.age".publicKeys = [ccr-ssh ccr-gpg mothership thinkpad]; + "magit-forge-github-token.age".publicKeys = [ccr-ssh ccr-gpg mothership thinkpad]; + "git-workspace-tokens.age".publicKeys = [ccr-ssh ccr-gpg mothership thinkpad]; - # WireGuard - "thinkpad-wireguard-private-key.age".publicKeys = [hosts.thinkpad]; - "mothership-wireguard-private-key.age".publicKeys = [hosts.mothership]; -} + # WireGuard + "thinkpad-wireguard-private-key.age".publicKeys = [ccr-ssh ccr-gpg hosts.thinkpad]; + "mothership-wireguard-private-key.age".publicKeys = [ccr-ssh ccr-gpg hosts.mothership]; + } diff --git a/secrets/git-workspace-tokens.age b/secrets/git-workspace-tokens.age index 72c66e124eadf2bae55a1cd39d84ba09246c4675..9accbd9998794657f1bf12112ad8369a06c84fae 100644 GIT binary patch literal 1898 zcmZ9Kxy$?r0fu$$Vx_Ik53StcGj}FISje4B?qqUIx?Gd{n4FU+Dy(3$m0)3G;j&nZ zc48sgY-gdBXrqXTsD&st%YF!g_z%3#`@j?B*-O?X<37w~-+iecb8v-$mv`PwQ}HrR z(HoGCa%KZK?k1N8Jw%a6h_d9t3@k;+Aq(Zz^#l{#@XXLfvLhCuD$d{)W@ZT13YIDv zx9&I}fEO8~h!BYa$E+wp7ui5a!GoLCV>XFpn;Z`32+41<;IzGYKb9tP0;W z_{O>wzQ|m=Mkhle)00^h=sIZYXrfT* zAClMID^RPT3WM_Ax{io4ACIS&RJj)j8YvJ(sc0o?Lx^Yr)RUlhAyAGhafphe^aYY6 zrqQ!?;U~d@Bj9?w9t?sw9_^;6H9mudI2Q_t$QNChD4=ojTJ3yFa3e;&C$gl(T4EGn zizpAjkFC&J2nh-2xOe}zV@n!QkOmyI<`K*mTJG$CvCG12FU`Zfw=NGb*TM86@DZ}1 zt!ZAjQSc*$f4T|W2I`#nEDe%?VkvHQpUlZlEbO)WP?}A(v=@U$ZP$;na=fq8H6cTo z*)I3XgU7Fgjnd8`k$7%i79gz@8rFPhbpj;i>5>X0RX?L{i%sl8C!KKCr}ORkbaO$C z!1hq%2F?Y@Fnzd`VA2NK9-4IVEUN5ygBgf9DqRtL2YPI5U zcPGQ&4H`x-?1E4z(0L8#H6h0gXzNDDX)+a+%5KOp@)RXXBm_rLpxqvxg?3Zn!=YLk zR>&2oElMLsdO&JBTwZ&LgkRdGwAZjc`o}XSK_hQ(sw+US?Q*Cg^x-pLC+JyH^0L%4 z=x?bQ?&h6Yy@EI(1ak zpcP7*mE3RIeNIjboFnp7FRj5`k4UFD=3g(pbz+>MT z=3&ecjO$`VvvKY&XXjdx(jilvXq0zTY~LP?WA=%R&B0d2PEm8f1jf`3!8fa$ z?P03h4o3e!P4qO?%HQ0s+|81)YTmr!ut$~>U|->*)sCdNX*_97T;DPiUwP&Lib59A zy7B8XR8Tjoqi6&d_)OwRCzYtXKgj`4m=~1#4-M7ce#yrynlix6?DZt9j2eXyKTdFi zYAb|`#dX2E(!|?Ho=~e-x53$NpblB8oony_nujs!`u#KltJS5!!`%2j=qX+Tp$Y3fA^EW`_6|y|KJPn{!BuWk3RA5Uw;34U;D?We)`WJeEl27TOWx(dgrZg q|K!tu{e}PgAAa!X-~Ro}(ieaH_J{BPMnKVDed}Le{harwZ+;A2+jE5g literal 1172 zcmZ9~I}76k0KoA@90D#*E=m{mB=+)d65*62ZIkBFypyKOk*0aHc|V(Ebx@r212~9- z$_eV&6~?*AalOVl>_aI3GAyIyXf&DX`!@_ z~~ND@oy9a2?i7;(&87(2Kmv_=y5mm5rOj%qXv+j7lE;b>2&fO>8b6+N`)=d4@b zvKrX$3FpwZ4n2BMG#tCjz?ZC?^l`jJcPq z0A9i+6z^R*E-o5Z(~1`4s;5@&G3Gpc9l$eI1m1DJo?JRlG2&2FwwKBRC~c??+p|De z9mG%_K`2DiI`b*&gwYb8bAyxXaW!p8)SOgs+=y9Wh!|a=n?B)51#9uXNvZ$@Cf(FH z^*puSF^DripRe0BWXqG|ko{IRTrYEUSS4@XaV0^euC0{S#zt0WOlf7Cfp>tEr)uJ< zr=2&G^CX?kjn-SFJsCQLYmD3M?EPG?V|Tt$;qKT-R-cgANU`8b-4vx=08}lgsaM~y zM7d233M;v~7ZJQlcQq*QYV5j3+3`R~NR;YY0HUZIhFgEPI}fRnT)GmdqT8V#=_=u7 z!*{l5>)9L(dAH2Ph2|n!NrnWNOU|c0kVQCVQjxgEgtRj9cuK742_!*8@hjmAb!yS} zXhF5Z+l<_gS-8pxPU1_Ki@j~`bcT#$gjvNm!;ttcN>C@mm=>^|sj+S*dnh4NKxos$ z)ljdBd?Tb>P6v+8TSZv0_3#AUe~!a5N)QOWn1hl=Z;SL2LbbUb`4c73A|^_Zb09dG zhCAAzOeU%WzhQSg!dMCrvD$njq;{6_vm-W>UkZMT)BUI^TVG;1N`MF#JdOjJ{=Zg( zwpK8U49{R6uM*o9S*D(;11l*kp3G1aFfxlZ^;~=LrKrVq3+z_pWmFJ`XSH^K@tr>Q z0})&Yqn-#h3Iq4ZQg{&!x~=?MgO>zRn=dZoCiL5I;e?CyH6vTR^2Xx6wp;-lkU9s& z%DAvJ%cVIQr4Xmx_CscIu7{Ll!Yfl`9O!Vb_#M;2^OIrA4A*J?K?LV$eEp@9AHEzkm2FTYgh~uu}i>?tJ}R`o~ibAN+#9|I?q( zJbd@gkH7uBNbK(J=ik5c?1L}9dVKo$)sH@XZ&`0&di=v%)bnpj=C_a1pRKpQ{7$>~ N;S0~}4 ssh-rsa /AagBw +L2Lpd0rWhkOWqfZhL7195OWxZc+0mi4CsMIqBs43kJmZht2hIav0fagJ047bBMZ5 +cxbULYcwJnDBKZz0Sriag1vKAL+ldGTlNiAtMTAo4pceX8/iA41iCYVsa/uSUoHn +eIoW3dN/dr/URf+0QyjYljO9EX6S7ZKxodqfiMUkmJSaag2+szom1G9gApzZN83X +oTDGNAOGYvU/ldPCK9jXl4OH7OQegbFbRHGAUkHPpB6toEbusmlDi8fn/D9a7JAq +0DwbsLCcT4S1BDAQfEN4fmTkgJy/nfLHFS1g9deDjgAylK1JWcHdV9Ex+nh6erGV +EuIBaMD9vtZI+Kmmq0xkPAPXGvcKTDmUYzCDZb2mIq8DqH8NkTAcrH6Q3uoW/rHd +cZSOr7sWChBPfcgC7mpvtSKpFoDEcNBqVT69/z9yu9829cr9F0FO8EcHcVvp/qgO +4jSBfuMYVpirxNGNFpAImyKJunvnSZSK2RwX/Ipu1ymlKZjicOIXF1jcIW5x7EEs +rqKsZoydHj8sS1Xd5bM5chLKRBsL8pnZntD92cjaUKhz/pjIZnx6vUfjsdhGedU8 +XG3KwLQtdEqDX2ZAckQZFa2dBs/3kkpR2v4Spek4/u3cGWLGQGA8wkBWo0UixoLB +QVhm34OlgEUwjW48XfPVToKmd+A7iUZ9dBocLfEW6R8 -> ssh-rsa QHr3/A -qduxR7BrDkrO4etAQAFRdZ+hEiPCC9QkB1tnaibi3gKJQkG8HwH/X0JjhJlyztJj -UxNKbQ5nJ6qpQZLwxP68frp6XN7ofUb5MnhMG4LWz9/rgZQgJCQHF4oNEWaHT5cc -kZdE0e/fNL2KJP+IA+IjEANeXk6TRYRYRUspDWy3go4sHt+bh+hWClVZb1kHFb1E -YAAaxQx5wn4bSdatdkX3FZoiKAIoECiDDiGryE0UMuHHl65W+CwQxBdlJc/Yd8dw -cL4COVc0kjKtdDgqBUFhp5YshZ+IiHv35dgwbJ4sUzOFuDcFAAT/DiShMblwyVyA -N7VsBbws8bOyztsTvqT40kg7pBmiHTEfqr7IzAJRPcwz5yfoEvi86tk7FxlR5XJO -R2Cf/9NdNjZQlwf19f+A7gBmRQtkHX4ZOd5PczWmrLKbzdIVM0DdCroqOwseCh2o -cPNgsV8O1+0j6WXOPuYdt8mpsCBIT6CIID78YdesmSF36XvD0ZZhe9xDov8ZNS2Y -r3k4NgXFPkGuqldAgteVxv259VazsVsXX0LoobX+aCVvtb9z2AfH+3EzikPCkzl2 -GQ4b4A2mpkim8++EmnA9DBMEnIcTb3w0OBx92kckYNKfjtEgpTmbVogJa0+wfXLl -bq5nLJEVsUZJE68JXldDO+5gV2Xp11H1vjZlCto/mP0 --> ssh-ed25519 q+UPnA xMPIbHuaa8Aq16doVvyVm8jo/yE+QiLdw7gzcRPcDkQ -ABw0RJIV/id1T682iMYgKBjQHv8QmpC0Axuh8oBgjgI --> K(;-grease i >P_wx V+ #A)4pj$P -j7qW+X/PhIcShM8tvw8+yiJ7r0U3MC/ZnFLLa+5uMcDh8A ---- Jpj8CohU3atn35QQswcX2jXY4CiPZYrOloYxItd1YDQ -~Wé·càNÍO¯oXAãBõ»ÁOæA¸æ‚ÔÆŠD§ÞÞC­FuŽ)UL1¶Nƒª|ZÏìÒruÚÏ}:tNz?¼P‚¹^ \ No newline at end of file +te/HLk+zfAG4+MOB5bB6J5M1mz+zLteZC4KknIPmXwfFrpgmzh1LykujBIwtl2ez +XNM7dvsX7VFFNt1r033TqlVPEbwzcf5C8KpGKUctk3UORmVErbqcIYS/x+KkzR7H +pi565rxB6yXE7zN3fK5Diqhe1TDb9BeLUVZPLtCo6QmWQ22lyt+50H72tvVX856N +PooEx/vTE7MMcokpGCWeuQEXvk7V+rkgCTsGSblZlnBftRaSFoeX/g+RweMZHm7U +yNfIodmgVQwaki+aZ6ceEpg6As6yFZuNhtNFreB93HnssiCKjBFLZzyOWNQ6xOOb +l3v3PQwNSXKyixmFBbvl8FxyNjXeCPZAUfyxJEiV1mB0Jbm9RBz7ET9E6Zr38MPx +j6DAbNyM2p+VaiRbtKAhs0CKxc8H2fAbuytG70K7m+3VzOEQWl0/QIglcwDIQhkT +ZF7/aibRHDk7GyBVuxjwmdkqdPsRqgh+HYYy47Vffkio+ukxkeaP8Sr/4KaZlmiS +G8OQO+h6AGkRC05HmEE+YN/3PhBf0ftQEtDevp3YGrvqpST1SMS0L2GRZ2jQ8A3U +gIW128skLqtX93KzFK+N1A6EjPbdpV0ZYgqTLsFHTy6Z5s7FIKskDcsVDVfDYeNf +f7dV/jVzd84I0UI+3uZ1YuYiJPSMRmuFDFmgtzUhZn0 +-> ssh-ed25519 q+UPnA BhHjEVW7Rb92rRy0e2OnX9uIIk8mhxHtgvgov0k4P2U +zx/PTSPbz2QHBEpsbVDrTwQRGxhb4nmt6ifSihnxAiI +-> ssh-ed25519 GVMLQg rxhOLvfV66Fna7+QrwMdVgLBufCJGye1b8zSmB5DyWY +WwEYozhj4uNUa4zBVBQFojZEG0WkCmVrvmErauGZLfQ +-> wyR-grease "#<'2 {sp +tDDDv7iDME2EsaJOWOavZO7jNlqdhkI1MV5CRc/a2tq4oPDYaTXKzl00u3Ta97Ca +4fEtqkwRr+eT3e2iZICvrATi5xlFSqeFjrV5YNpbBQlusBK/njYv4A +--- vjabJh2rRDsBFnlvW+r/YwvGVb9k7HzQe9la0ZxFvW4 +¯Úß/fBÿÒ4¦ßÅñ Jª&£0š/óGÑ‹fõN”K5‚¦Aw<ÁRú°‚œ¤£üšÃ³®;’]¶™VV toч; \ No newline at end of file diff --git a/secrets/mothership-wireguard-private-key.age b/secrets/mothership-wireguard-private-key.age deleted file mode 100644 index 374b6fc..0000000 --- a/secrets/mothership-wireguard-private-key.age +++ /dev/null @@ -1,9 +0,0 @@ -age-encryption.org/v1 --> ssh-ed25519 q+UPnA 7RAJbAW7p/kUyAG7VQlVG2Ri86F13GCVw7uOGck5Yms -KJQCDEH6PQF8H4uUFp5cuvtLb4Yldvl35NXqbYyxUYQ --> 2x%m?X4r-grease [L7Jb/. xgMVomN[ -in0zvAfoC0s/CLqNviUa2NfGJR1R4BjbkKCzNYsjJd7JUG+R1hda7Vku7SQ5yA1D -SzSeDISN7PK6dVBDlt2vzgqZnJpNswnSu23qdlfiQ2f9N/LA7gKD9uB5YF5wac2h -rgY ---- 3m0T9+VQCfTh6uuvoilEvtu57x6UbXsRf73k40O2v9k -¢‘]jòßí¦£SUt ssh-ed25519 GVMLQg 8234gUExVmFvBd15Y8mDZMQN+JB0iF19Aco06QOF+WI -pF4KkrffJ/JyihbqyzssHWQj4KTAT9FaO6d4C7W3fjQ --> C_|=?Ris-grease g3jg)xQT BnPMOr^ C3 -CTxz+ixS9zskTgznQf9x80hgX/maxeYS5GQloV9ARTs0g1q8sR4XWWcM28c7RKoM -vxfC5QDCpmXaCiDG7s/xaTXF0GDSAyuFfcUCru0L0aOnz2ZGlWllKZ4 ---- n10P3gZZFs/X9zqMlV+jNgYd3nBdt0UJEqvB0GDDgRs -0sàÇwÌÝN©hÚ:¾ØR<.6}?Šä!µ}ená `5lÉLm¥²™ïsYÁð˜šø~d0~Å–x‡{¼BAuqüàíáȘÒž \ No newline at end of file