From 7fcbc0bddb4ce43ec18a4866d9dc4db8db5a389b Mon Sep 17 00:00:00 2001 From: Niten Date: Mon, 9 Oct 2023 11:35:45 -0700 Subject: [PATCH] Make secrets work again... --- lib/fudo/secrets.nix | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/lib/fudo/secrets.nix b/lib/fudo/secrets.nix index e79c9c1..f934d04 100644 --- a/lib/fudo/secrets.nix +++ b/lib/fudo/secrets.nix @@ -39,7 +39,7 @@ let { source-file, target-file, user, group, permissions, ... }: { description = "decrypt secret ${secret-name} at ${target-host}:${target-file}."; - wantedBy = [ cfg.secret-target "multi-user.target" ]; + wantedBy = [ cfg.secret-target "default.target" ]; before = [ cfg.secret-target "multi-user.target" ]; serviceConfig = { Type = "simple"; @@ -60,8 +60,9 @@ let inherit secret-name source-file target-host target-file host-master-key user group permissions; }; - ExecStop = pkgs.writeShellScript "fudo-remove-${secret-name}-secret.sh" - "rm -f ${target-file}"; + ## This is too aggressive about 'stopping' + # ExecStop = pkgs.writeShellScript "fudo-remove-${secret-name}-secret.sh" + # "rm -f ${target-file}"; }; path = [ pkgs.age ]; };