diff --git a/.sops.yaml b/.sops.yaml index 2f7c075..aae7f6c 100644 --- a/.sops.yaml +++ b/.sops.yaml @@ -6,7 +6,7 @@ keys: - &beleth age1xf86ak2hu5efux42au4x7wlxqpxqpuld7kd6nnr2qzhl662wy3vq940d4p - &lilith age13704a3s08stwndvduk2qsqmkg703utsn96ak3gzexggvrdx3cpxsrlx92n - &alastor age1cjglrl2qg7ursfradsspat4gz50pqgdj2dcjqngwx5rrf7el83mqj5vf4h - - &yosai age182mmgwl4w0qffsvjx0v200g3hp5xu478zrkcfvadzhz6u5aqmuvsswmr6z + - &yosai age1nnn0n654nks0upg0f22l7dx4efdcjw47m2kkvn790ewjm7yxeagqc66jgp - &seraphim age14vh330hj00gxhprjr3ajqq0gqwvt2m8epqstsvmpx6ta8wu5usvq4znjha creation_rules: diff --git a/hosts/x86_64-linux/yosai/default.nix b/hosts/x86_64-linux/yosai/default.nix index b8f9202..b2a0657 100644 --- a/hosts/x86_64-linux/yosai/default.nix +++ b/hosts/x86_64-linux/yosai/default.nix @@ -36,12 +36,13 @@ boot.loader.efi.canTouchEfiVariables = true; boot.initrd.luks.devices = { root = { - device = "/dev/disk/by-uuid/4df4ef63-896b-4954-98b4-77bf9f4297c6"; + device = "/dev/disk/by-uuid/a608ad91-5899-4dca-978b-47c885ed8418"; preLVM = true; # allowDiscards = true; }; }; + services.blueman.enable = true; security.pam.loginLimits = [ diff --git a/hosts/x86_64-linux/yosai/hardware-configuration.nix b/hosts/x86_64-linux/yosai/hardware-configuration.nix index a97cf0f..002dc1c 100644 --- a/hosts/x86_64-linux/yosai/hardware-configuration.nix +++ b/hosts/x86_64-linux/yosai/hardware-configuration.nix @@ -17,16 +17,17 @@ boot.kernelModules = []; boot.extraModulePackages = []; - fileSystems."/" = { - device = "/dev/disk/by-uuid/778c036a-5e13-4946-8cdc-9aad0309713f"; - fsType = "btrfs"; - }; + fileSystems."/" = + { device = "/dev/disk/by-uuid/e8fedd91-253b-4112-a8fd-5c874ea81116"; + fsType = "btrfs"; + }; + + fileSystems."/boot" = + { device = "/dev/disk/by-uuid/29CC-9B85"; + fsType = "vfat"; + options = [ "fmask=0022" "dmask=0022" ]; + }; - fileSystems."/boot" = { - device = "/dev/disk/by-uuid/76AB-764E"; - fsType = "vfat"; - options = ["fmask=0022" "dmask=0022"]; - }; swapDevices = []; diff --git a/secrets.yaml b/secrets.yaml index 0187f8c..64fb01d 100644 --- a/secrets.yaml +++ b/secrets.yaml @@ -23,56 +23,65 @@ sops: - recipient: age1jmqdy4ntgmunnh485qcvxg9yvc2rcvrwf8nq0jg8n4c5al7sza2qq3c80d enc: | -----BEGIN AGE ENCRYPTED FILE----- - YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBwVGlqQVBIWkZHZlBHbjUw - L3JaSk5odVg5eWZPK2NSSkdIaXM3NjdPWlV3CkhxcmNsMm1JWnNsczVmMUxKRDhM - cVNIQTMwd0ErdFZ0Ykp6QXhTREtFeG8KLS0tIE52K21WakRpOTBjRVJtd2lIajl4 - bVNjVGMyWGYwOHp6ZkJkdlhmRDAyQXMKOjhJyV7vL7Lyh9WlGpCOxQHDKtkDAhZx - FtEQti4Ch70fqiCdVtBPKkT5/6IVcxrsZtit+OJcsnvMWSGLhQCuOQ== + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBzZlllLzROc2NEU1pRQ3dJ + RXdVdUNubjEzeFRPazRjdFNNcGsyUGtQWVU0CjlKZTlYdWJvdHF6WGViYU40Uk1m + UUw3U1VkaytDZXNtZWlQb25PMjVIMUkKLS0tIHBtcVRmYXZqLzNNOVF2S1FpeCtX + QWdFckVDQnk2R1lpNXNicVk0K3Z4eXMKq0XTOkPepGAbU/4DxuQWOBCZnElyraaE + hejzEebwaNiRUh8Np1J9hPYYX5F263f4+/EDrMsTC90hIHtOqdtQLg== -----END AGE ENCRYPTED FILE----- - recipient: age1lznc3dadzpc7vllpvnpdf8samadleep7sxfg0dnpzwl0nngzdv7suu73rh enc: | -----BEGIN AGE ENCRYPTED FILE----- - YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBXT0JjRm16M1lJWFBhZ3Bs - RkVkcHJuQmVic0E2UmhnNHFEYzVMWnBQMFYwCmoxQXM0MlV6VysrQTVLVWZZRjQ3 - alRjYlBmTkFpaWo4OGtVeVdRTWdVSXcKLS0tIGFxR0ZNSjdSU0FtaDYvN1I3Vlg4 - N0xSQU50NUtQY2hPeDJyS1VGOHYzOTgKxhAcU1ivpPZooB4KQ5fKE4qTCdkF5sez - HKm2ooNGClmsw4hBrVFjV6+YXwSOTZC9HzjuTNZEbCqhrezS8KKsMA== + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBkS0kwTEl2NHlBclBmNENW + NXUyVjg1a3FzQjlSWkNTOURpcnByNlhkNTJjCllFZDUrUSt0VFM3bit3T1M1R2VY + akh6ZnAyeHZSZlh1ekNPL3hwUkw4VVkKLS0tIFlxUVFQWXVJOW1OY2xDRTBLUVFP + c0docHNTZXVHUXNJMC8vRm41S0l5ODgKqjbBddCAP0z6TtRB1p+zKryWMu6vSyMv + BqFHS+E0mvaA8zqV7+mnzb8xIoCTDj5l96T3ks2OV3GgTwnEhZcU0w== -----END AGE ENCRYPTED FILE----- - recipient: age1xf86ak2hu5efux42au4x7wlxqpxqpuld7kd6nnr2qzhl662wy3vq940d4p enc: | -----BEGIN AGE ENCRYPTED FILE----- - YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSAyRDg4Qi83VUp5WnlVYTl0 - UWVGTnZhOVZqcHJzdDRrdzFlNlIzWlVXZHl3ClBFUFgwK1UyQUdTZVMwTlMrSFZC - VmFrOThLVEJqNVV5aU5yKzhkMmRNREkKLS0tIHREL0d4Yk5ZUkN3MlQvdkdYa2ZE - VlZwY2YyT2MxSGQyaVVTYXdXdDN2WU0KSx3EV/IGylQmbfBKv3lVDbgqho4n/yqh - oaKmjI/mL4x8ckDLQ7GxnH8XwEuGaZS3cSUO/OUjk4UgFC6FY1dPzg== + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA3SEFka29qV1NEQklyQS9I + TVBRRXNTcmhXMjlXeCtkU1RMMTA4Vi9qeFV3CjQ2VmF4NUsybmpOLzhiTXZhV25O + WVQxSkxicktHRGFLWERpWTFVOHYvQ1UKLS0tIFRJVzI2bUl1WktDV09kaVB3WGg3 + dnFudVE2eTJMTENKaVRSVVpTNTdXV0EKLe63dG2MQu+Sjae6CFp/jXQa7x/tZUHJ + SQ0ZLY5JfnoqyZwuidvZd26rMXcT9eTGF9oceUiZMNABya77TSGxuw== -----END AGE ENCRYPTED FILE----- - recipient: age13704a3s08stwndvduk2qsqmkg703utsn96ak3gzexggvrdx3cpxsrlx92n enc: | -----BEGIN AGE ENCRYPTED FILE----- - YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA1OTBVVzN3V2VEU245SS9O - WTZGanNDSUVsM3VqYUZVc2Z4ZmZXS2xsVVJBCkhKY0RNS1IvYWRFdS8zZFpyWEJZ - dit0TXRqb01xVmFLQ21JMm1oT0haY2MKLS0tIGpYY09JZkorc0VJemVXcFVvZitx - QUNhU0FPU2xvTC95dk9aVkNPNDdNelEK/nPBxNdWWwhOVMjKS/IxLuGXBdRVJcAg - VRGpNqDFjpmf7IMGEmGvH77NPGbg89DTuOg6xnNEDkbc522k4vuIVw== + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA5bThnbkZRcUNkRlJjTjVh + WTlnVTJPNFpmUUgrb3AxK1N4L283SzFyeFIwCnI5WktaK0UxelBoM0R0VVdMVmZv + cmw3SmdXSExHNzlNU2NtTmpzMVhXd0kKLS0tIFlrb2JTaW9XcXFRVUxHOVhNdFZi + enhzRG5PQ0lEd3FYVXlqOWhRREhua3MKqBG6T42sf6NBt/mfjfD81N5dWZYoqLHo + wO1G+1Q1/eTeoVHHdLFKT28T4bWSusY86SVb0Hb/q+AvFx0p+sa2Vg== -----END AGE ENCRYPTED FILE----- - recipient: age1cjglrl2qg7ursfradsspat4gz50pqgdj2dcjqngwx5rrf7el83mqj5vf4h enc: | -----BEGIN AGE ENCRYPTED FILE----- - YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBNeE9RMndsc1BZeG5OUHZE - ZkJ2eTlIS0s1TExub1dOV1BUSHFONFViVmd3CjR6d015M2Mra25LQTEwOVRjQTF4 - MGVEdTZXMzNOZXFHaTdXR2c3NTluWk0KLS0tIFg2MW10UW05Wm1iQUdsWVB1cGZr - c1NmQzVtRmtQMy85TURoMkQ5QUN6VDQKe3TxnxA/aMqml/9Dt38J/ThhLdPJFObR - wE4UITAKmeelt3tAIl5Da+jZp1dSCYIulwDla280KXgmJg3rJbHKxQ== + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBMdzdScy9NOXB5b2ZsTkty + b1RJWDFLQ1ZuU29sVkVyZm1ublBhQTVEU3kwCjBuUW52V2d2dEV4cFVFSlpjcXE1 + V2U2TW1pdllvZTNJbUEzSldRVEFiODgKLS0tIGt5blZNMTQzK1hzUlJUcndwOTEx + elo1MlBmUnVXdlFSWWVNb3VldVU5T0kKEObKFDIdAbK1UXfOfiSBKvKCz1jodbUz + R+QlkHr7/CKyDGI6WYeb8ChHxPwvCgTZE4IaJHB39aeGWuXGOr38Ew== -----END AGE ENCRYPTED FILE----- - - recipient: age182mmgwl4w0qffsvjx0v200g3hp5xu478zrkcfvadzhz6u5aqmuvsswmr6z + - recipient: age1nnn0n654nks0upg0f22l7dx4efdcjw47m2kkvn790ewjm7yxeagqc66jgp enc: | -----BEGIN AGE ENCRYPTED FILE----- - YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSB2RGtGeEpBYkthVFcvcDBO - Slhob1R3c0pabVVsT1dTL3A1T0hQSjZpV1IwCms1YXI4c0xlOXBQME9pTTZZZHpI - eTA3dDBGWnMxT01qamhOS2o4U2VhZGMKLS0tIE1kMTNRUmdOdjI4ZElRK3pzdkpO - VGtmR3doRnppdVVXMVhsZXpQZWZISlkKSS7vbqi2XCewPlYNTpkHiJmoL9vOKH6y - uO0HiakJeBuxji7v40hyBtTYsdJcm/TtCZeGk/NwGW8GBGe3LCd29g== + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBacTRkNnZEV2VjbW9CamdH + c2ExZ0llN2pycCs1a0RKcG9ML3haSHZZQ1dFCjEwQmlQNWlkKzRqSGlRb3d1VVRo + R3NLdGFkeFBUNllwV2FZKzJDdG5IMmMKLS0tIHRYbk1OOFZ6QW9hVW5GSWRaTlRT + aFFEdTE5RFl0MWlSNXJIZTBNUFZSVk0KF07I1QeJBrliB0De2lDuW2Y6OWgfPj9Y + 9yDN1zJrz71NcjQoEHDAl2Tb9kBmsVl2kkOYaLnKi+qq7Qr2LXuYXA== + -----END AGE ENCRYPTED FILE----- + - recipient: age14vh330hj00gxhprjr3ajqq0gqwvt2m8epqstsvmpx6ta8wu5usvq4znjha + enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSArMkZvSS9pVW1ZbzZPakZO + Z1FTQ3NON29CRWQ1UDBSbmlRc0lQRjJEMEc4CjZNSVVhQ2psQ1hvaW1DMGRJZVJB + TzkyY3VNQmpuWTYwZzFBZUJBT0djMXcKLS0tIEFCV0d2WjExWmtBbTNRWnlaSWx1 + aEN1NWxGelg1VU13Y1Jrc2cvQlcveW8KXiGOQEgtaiWRqVppXFUeBuCz9QmxgYc1 + QZhMmIY9cVX0IwfEoNqNnfUCx2T3jNpEMpIgJ9bEdRpK45rmPHj0Vg== -----END AGE ENCRYPTED FILE----- lastmodified: "2025-02-20T19:21:05Z" mac: ENC[AES256_GCM,data:r62PnTridjrsxwAf9aWCHjsbjuCPwGAOLSjmfSlw4Nu7EKdn9a9ht6cTjn2k8S9R/hF95ZmrzcWeBopWVNykiuXfMtXnCbSDgAnPbBViNDt4ZMZAW+yx1ggprOynjhJ6nooqZYwy/wbUcvKdSKXiAEi+2O16H4TBMmw/g6kB+bo=,iv:4w7Engp5tYk/2pCE+kfb1jDfF/EbbHTTWr7gJsIjfcE=,tag:dq6sYkz6ki4V2lM5NhZJyg==,type:str]