Make secrets work again...

This commit is contained in:
Niten 2023-10-09 11:35:45 -07:00
parent db5c0b7cd1
commit 7fcbc0bddb

View File

@ -39,7 +39,7 @@ let
{ source-file, target-file, user, group, permissions, ... }: { { source-file, target-file, user, group, permissions, ... }: {
description = description =
"decrypt secret ${secret-name} at ${target-host}:${target-file}."; "decrypt secret ${secret-name} at ${target-host}:${target-file}.";
wantedBy = [ cfg.secret-target "multi-user.target" ]; wantedBy = [ cfg.secret-target "default.target" ];
before = [ cfg.secret-target "multi-user.target" ]; before = [ cfg.secret-target "multi-user.target" ];
serviceConfig = { serviceConfig = {
Type = "simple"; Type = "simple";
@ -60,8 +60,9 @@ let
inherit secret-name source-file target-host target-file inherit secret-name source-file target-host target-file
host-master-key user group permissions; host-master-key user group permissions;
}; };
ExecStop = pkgs.writeShellScript "fudo-remove-${secret-name}-secret.sh" ## This is too aggressive about 'stopping'
"rm -f ${target-file}"; # ExecStop = pkgs.writeShellScript "fudo-remove-${secret-name}-secret.sh"
# "rm -f ${target-file}";
}; };
path = [ pkgs.age ]; path = [ pkgs.age ];
}; };