-
Notifications
You must be signed in to change notification settings - Fork 0
/
flake.nix
57 lines (53 loc) · 1.72 KB
/
flake.nix
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
{
description = "Homelab";
inputs = {
nixpkgs.url = "github:nixos/nixpkgs/nixos-24.05";
nixos-hardware.url = "github:nixos/nixos-hardware/master";
flake-utils.url = "github:numtide/flake-utils";
sops-nix.url = "github:Mic92/sops-nix";
};
outputs = { self, nixpkgs, nixos-hardware, flake-utils, sops-nix }:
(flake-utils.lib.eachDefaultSystem (system:
let
pkgs = nixpkgs.legacyPackages."${system}";
sopsPkgs = sops-nix.packages."${pkgs.system}";
in {
devShells.secrets = pkgs.mkShell {
packages = with pkgs;
with sopsPkgs; [
ssh-to-age
sops-import-keys-hook
sops-init-gpg-key
sops
];
};
devShells.default =
pkgs.mkShell { packages = with pkgs; [ git-crypt ]; };
})) // {
nixosConfigurations = let
buildSecrets =
builtins.fromJSON (builtins.readFile "${self}/secrets/build.json");
in {
mirage = nixpkgs.lib.nixosSystem {
system = "aarch64-linux";
modules = [
./hosts/mirage
nixos-hardware.nixosModules.raspberry-pi-4
sops-nix.nixosModules.sops
./nixosModules
];
specialArgs = { inherit buildSecrets; };
};
chakra = nixpkgs.lib.nixosSystem {
system = "x86_64-linux";
modules =
[ ./hosts/chakra sops-nix.nixosModules.sops ./nixosModules ];
};
water = nixpkgs.lib.nixosSystem {
system = "x86_64-linux";
modules =
[ ./hosts/water sops-nix.nixosModules.sops ./nixosModules ];
};
};
};
}