specify systemd-network as owner+group for wg secrets

This commit is contained in:
Konarak 2025-08-18 00:09:08 +05:30
parent f0f0229345
commit 61dbfd2da6
Signed by: konarak
GPG Key ID: DE5E99432B548849

View File

@ -73,9 +73,14 @@ in {
};
config = {
sops.secrets = lib.mkMerge (map (cfg: {
"${cfg.serverPrivateKeyFile}" = { };
"${cfg.clientPublicKeyFile}" = { };
sops.secrets = let
def = {
owner = "systemd-network";
group = "systemd-network";
};
in lib.mkMerge (map (cfg: {
"${cfg.serverPrivateKeyFile}" = def;
"${cfg.clientPublicKeyFile}" = def;
}) interfaces);
assertions = lib.mkAfter (secretAssertions ++ uniquenessAssertions);