1
1
Fork 1
mirror of https://github.com/oddlama/nix-config.git synced 2025-10-10 23:00:39 +02:00

feat: use kanidm secret provisioning

This commit is contained in:
oddlama 2023-08-27 01:17:11 +02:00
parent 522de920bb
commit 7c48e51320
No known key found for this signature in database
GPG key ID: 14EFE510775FE39A
9 changed files with 126 additions and 105 deletions

View file

@ -20,6 +20,13 @@ in {
inherit (config.services.gitea) group;
};
# Mirror the original oauth2 secret
age.secrets.forgejo-oauth2-client-secret = {
inherit (nodes.ward-kanidm.config.age.secrets.kanidm-oauth2-forgejo) rekeyFile;
mode = "440";
inherit (config.services.gitea) group;
};
nodes.sentinel = {
networking.providedDomains.forgejo = forgejoDomain;