Make secrets work again...
This commit is contained in:
parent
db5c0b7cd1
commit
7fcbc0bddb
@ -39,7 +39,7 @@ let
|
|||||||
{ source-file, target-file, user, group, permissions, ... }: {
|
{ source-file, target-file, user, group, permissions, ... }: {
|
||||||
description =
|
description =
|
||||||
"decrypt secret ${secret-name} at ${target-host}:${target-file}.";
|
"decrypt secret ${secret-name} at ${target-host}:${target-file}.";
|
||||||
wantedBy = [ cfg.secret-target "multi-user.target" ];
|
wantedBy = [ cfg.secret-target "default.target" ];
|
||||||
before = [ cfg.secret-target "multi-user.target" ];
|
before = [ cfg.secret-target "multi-user.target" ];
|
||||||
serviceConfig = {
|
serviceConfig = {
|
||||||
Type = "simple";
|
Type = "simple";
|
||||||
@ -60,8 +60,9 @@ let
|
|||||||
inherit secret-name source-file target-host target-file
|
inherit secret-name source-file target-host target-file
|
||||||
host-master-key user group permissions;
|
host-master-key user group permissions;
|
||||||
};
|
};
|
||||||
ExecStop = pkgs.writeShellScript "fudo-remove-${secret-name}-secret.sh"
|
## This is too aggressive about 'stopping'
|
||||||
"rm -f ${target-file}";
|
# ExecStop = pkgs.writeShellScript "fudo-remove-${secret-name}-secret.sh"
|
||||||
|
# "rm -f ${target-file}";
|
||||||
};
|
};
|
||||||
path = [ pkgs.age ];
|
path = [ pkgs.age ];
|
||||||
};
|
};
|
||||||
|
Loading…
x
Reference in New Issue
Block a user