diff --git a/modules/hosts/nixos/hetznix01/default.nix b/modules/hosts/nixos/hetznix01/default.nix index 20e31b3..fd63a63 100644 --- a/modules/hosts/nixos/hetznix01/default.nix +++ b/modules/hosts/nixos/hetznix01/default.nix @@ -42,7 +42,7 @@ fail2ban.enable = true; postgresql = { enable = true; - package = pkgs.postresql_16; + package = pkgs.postgresql_16; }; uptime-kuma = { enable = true; diff --git a/modules/hosts/nixos/hetznix01/post-install/default.nix b/modules/hosts/nixos/hetznix01/post-install/default.nix index 30200b0..a0c9b3a 100644 --- a/modules/hosts/nixos/hetznix01/post-install/default.nix +++ b/modules/hosts/nixos/hetznix01/post-install/default.nix @@ -34,6 +34,10 @@ owner = "${username}"; path = "/home/${username}/.private-env"; }; + matrix_secrets_yaml = { + owner = config.users.users.matrix-synapse.name; + restartUnits = ["matrix-synapse.service"]; + }; mqtt_recorder_pass.restartUnits = ["mosquitto.service"]; owntracks_basic_auth = { owner = config.users.users.nginx.name; diff --git a/modules/hosts/nixos/hetznix01/post-install/matrix-synapse.nix b/modules/hosts/nixos/hetznix01/post-install/matrix-synapse.nix index 6770ab8..74ac820 100644 --- a/modules/hosts/nixos/hetznix01/post-install/matrix-synapse.nix +++ b/modules/hosts/nixos/hetznix01/post-install/matrix-synapse.nix @@ -6,10 +6,10 @@ in { configureRedisLocally = true; enableRegistrationScript = true; extraConfigFiles = [ - config.sops.secrets.matrix_secrets_yaml; + config.sops.secrets.matrix_secrets_yaml.path ]; settings = { - public_baseurl = "https://matrix.technicalissues.us"; + public_baseurl = "https://matrix-test.technicalissues.us"; listeners = [ { port = 8008; diff --git a/modules/hosts/nixos/hetznix01/secrets.yaml b/modules/hosts/nixos/hetznix01/secrets.yaml index 9f799a8..4abb301 100644 --- a/modules/hosts/nixos/hetznix01/secrets.yaml +++ b/modules/hosts/nixos/hetznix01/secrets.yaml @@ -1,5 +1,6 @@ local_git_config: ENC[AES256_GCM,data:BulcGoJ85+BA3maqbMewUdaNOl3feaJMq/4yZL8Y8SLOHqzmA/DUO7k=,iv:V7wpSiEQpt7AhKd+MUyGqTsO6YZovpkj+AaqpLnfRM0=,tag:7f3fFzQX3bpjokVPnUKDPQ==,type:str] local_private_env: ENC[AES256_GCM,data:OFcCaE9/hpd6JIoUTTxg0pEFL3rkUE3G+JzP/wjFXpa/AJa2Rr0Kv42Pu+iwgPMWgcpp50ChjVxGvbceNQ==,iv:I2LyWwvdMdE4wKLb3udLVMu3jFsvYR1ruZvaVt9GG7c=,tag:tBPmlNr0iNdLRU1GIRV2mg==,type:str] +matrix_secrets_yaml: ENC[AES256_GCM,data:El9razifgbJEaJd9NccOZX1RuZQHRyw6Yg7TY4G8vDtD2w7KxnHUG7bcpIQodh3I1GDjj3gQcHXP6HNs0zS7UjaoGltDt3mHnrhqkvvDW/RgAGrJ9nUsQitB3yhF51PG3IOK1SSbIBk+Pr/wQWbs11ic8i+fGJ6yPcv8k/X5Az8rKmDqDuZh9KUvSB3SQ9J/roOZ+HDb8fv1VmMgZZNGmkOUGZupZkKd+kc2rWrBl5zHTd9XUH6oLk2EwRDufR7T,iv:xCG8xJ7A1bFwK9v1+XJ+vSp/GXCTwdKCL4H/uQ6h4fQ=,tag:Z72quTZvJUMLJ+VJVsTKrw==,type:str] mqtt_recorder_pass: ENC[AES256_GCM,data:N44nv2mk5zguWXNHdKsxhoKUjiduD1hzsAb6,iv:aLudKuUBTPXgtAF33exELH/PESD0CqoDaydeqdhcmbA=,tag:3lhrqO8jxJiRHWZjWSRa0g==,type:str] owntracks_basic_auth: ENC[AES256_GCM,data:GX1U1uf7+erE+g9GzhXK5ED2QicfcbpRCwpJDw6Zr9X2FtdMYleH5mhLxw==,iv:PflRq+P50+oFf4wv5wwlY6V9bApGuJ3tlYTvJZ5mg0E=,tag:VHBY5qv7rX74DGURsYaWpw==,type:str] tailscale_key: ENC[AES256_GCM,data:Bl00WuIrLvxmt7aNsoXC6G7XFls7waZMzdfo/MsEOZl/i3wHwrjrmgwd3V4GkaJ42UjrC1OLobrkuLves4w=,iv:tlCu0EWgvhvs1ANdtQr7KWHJ2RjpHniUm/rFC4L/MHs=,tag:+8eov9w+SPGZPnjMdrN8gA==,type:str] @@ -18,8 +19,8 @@ sops: WkI4ejBaODI0d0tjWHpTT3VWTXNyaXcKMDtvHN4gcZqBNslyC+NwYW05zgs8QuPV W6EktAz+xu6kx5BJbli5GkUFmj52AtEGIqZ1Sr4a0pKQACC87XcTQA== -----END AGE ENCRYPTED FILE----- - lastmodified: "2024-06-16T03:36:06Z" - mac: ENC[AES256_GCM,data:KkJ7awR2HwH8MBHrDzOifwD6ePACWsGFaNg8/eixKvb+/V4k2NkOxZPzdemcqMaCPCzhX9bGlE76MGy9y6JWvln+yKkBx7uilSdfGu5bVnMQY0JT8r2nW4tCfJ1VpLOxdvcw8pUjeK/oizvUolk7DJ1PecrPQuSmhGkOAL6h6dA=,iv:nd0F7sU9hYOu3qb0kXSstRt8M3QDmciSs5ArtiXI6XQ=,tag:gGG8NnO690UrTq6y4NnK9w==,type:str] + lastmodified: "2024-06-18T01:49:28Z" + mac: ENC[AES256_GCM,data:ckwiYte2TP4ufiFkmX2cTuNNae+VizjQ/CM1b1m3Lz3Vo5utd1g82loChQS95s9lr1dmKljuUbklHzg74JbNCeFky4f6od5CEydq/R9dXFTZKBen9cLcdvTVQ0i6E9rZS0t6ohy3wMFyJxw0ss6Zyykd0cqQOPuFBpyHmKFZTVs=,iv:85G4CxlLPD0Ac6KxRYaZ+4H9uj8Co6nmh1bbL6s3MVI=,tag:oyRhgR2Uf7lWFIlH5FKAvw==,type:str] pgp: [] unencrypted_suffix: _unencrypted version: 3.8.1