This is just tweaking at this point...
This commit is contained in:
parent
169cf84263
commit
1e5cdcba79
|
@ -39,9 +39,9 @@ let
|
||||||
{ source-file, target-file, user, group, permissions, ... }: {
|
{ source-file, target-file, user, group, permissions, ... }: {
|
||||||
description =
|
description =
|
||||||
"decrypt secret ${secret-name} at ${target-host}:${target-file}.";
|
"decrypt secret ${secret-name} at ${target-host}:${target-file}.";
|
||||||
wantedBy = [ cfg.secret-target "multi-user.target" ];
|
wantedBy = [ "default.target" ];
|
||||||
requires = [ "local-fs.target" ];
|
requires = [ "local-fs.target" ];
|
||||||
before = [ cfg.secret-target "multi-user.target" ];
|
before = [ cfg.secret-target ];
|
||||||
after = [ "local-fs.target" ];
|
after = [ "local-fs.target" ];
|
||||||
serviceConfig = {
|
serviceConfig = {
|
||||||
Type = "oneshot";
|
Type = "oneshot";
|
||||||
|
@ -57,7 +57,7 @@ let
|
||||||
fi
|
fi
|
||||||
'';
|
'';
|
||||||
ExecStart =
|
ExecStart =
|
||||||
let host-master-key = config.fudo.hosts.${target-host}.master-key;
|
let host-master-key = config.fudo.hosts."${target-host}".master-key;
|
||||||
in decrypt-script {
|
in decrypt-script {
|
||||||
inherit secret-name source-file target-host target-file
|
inherit secret-name source-file target-host target-file
|
||||||
host-master-key user group permissions;
|
host-master-key user group permissions;
|
||||||
|
|
Loading…
Reference in New Issue