diff --git a/secrets.nix b/secrets.nix index 3b3ede4..c0d5047 100644 --- a/secrets.nix +++ b/secrets.nix @@ -8,6 +8,8 @@ let "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKaDPqRJHoqgY2pseh/mnhjaGWXprHk2s5I52LhHpHcF millironx@bosephus"; odyssey-millironx = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIN9Aj7BtQp1Roa0tgopDrUo7g2am5WJ43lO1d1fDUz45 millironx@odyssey"; + corianne-host = + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHKKkucebeb1GcerOZAAs5GQsgTS8kXw5W41b9Fy9+hp root@corianne.local"; corianne-millironx = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOgL2lO9RJBdQYANoxGyWXcNKi5/NZkRHHo/rNqaYMc/ millironx@corianne"; harmony-millironx = @@ -26,5 +28,6 @@ in { ++ [ bosephus-host ]; "secrets/pihole.age".publicKeys = system-administrators ++ [ bosephus-host ]; "secrets/ansible-vault-password.age".publicKeys = system-administrators; - "secrets/darwin-policies-json.age".publicKeys = system-administrators; + "secrets/darwin-policies-json.age".publicKeys = system-administrators + ++ [ corianne-host ]; } diff --git a/secrets/ansible-vault-password.age b/secrets/ansible-vault-password.age index 99a96bc..d833716 100644 --- a/secrets/ansible-vault-password.age +++ b/secrets/ansible-vault-password.age @@ -1,13 +1,13 @@ age-encryption.org/v1 --> ssh-ed25519 il3lzQ Ni2CHjeijXHfF62cUqVTm8MAOn6rRg8UrhqN6xvdkyk -DsT0Ysx88FlCLeRzoOGctX7KqatX9/UCr5WdtdLJAf4 --> ssh-ed25519 1g/xww jRn91F29sISMyi41anAlzVCzt1t1DnUqxtryqkTQPlM -cysgZLQR0YhiJYXBl59DjKbm+N8FnjA46wkQtnAzBFA --> ssh-ed25519 +kBihw t6wlSnDKGgSzGhNJnryXVbDR40DATaV3fHovtI/u7zo -zOyCZtzfLKeer9K6SMpfTxn6El4HB7gQFQqLOxIYB5U --> ssh-ed25519 dbKeHw cn+8WTwis58bYm2pfEra6LeLvzEZ8GhZrOEeN+kkhCM -fnlUAj8JtG8+r7Cj8xYUgF+JM6Pwqawn4sGI1LOeN78 --> ssh-ed25519 Svnssw zmDBR8TdRZ9NzNhwPYRN6c8naTxAkULyUZpKgk7Gshk -0XCwpegEIlGXhnzLLUtmciKQiYiZRgnSOSvCcYeXXk8 ---- D/lZ36n5sVste2NWfdOx8/klPh0CTmMjVQN74KIqDRY -]%C}NO"v#˱t_Q;^*!+<+dB/K` \ No newline at end of file +-> ssh-ed25519 il3lzQ 8BY+QUEGqILKLs6ROw7llEOhx0GgrfFeKDcEgHePUFw +SPiG48tkp5ewFc6/uNj+541B6YJODGmDFEbET2BfoZ0 +-> ssh-ed25519 1g/xww HyUG/jNJgHCceV/9vaaoSHc681x6Gg/uY+RIfQxIBxU +6XVufQ4A9r8HPU9QLZ/idx3NjDf+UeKVMhtk9+Awy4E +-> ssh-ed25519 +kBihw XjhEk6TF6M5OalqVQNpAemlmgMIJnfuH6M600DnJql0 +3zQPJZcsfnbUqRf5XWTJNbyqMb/rsSBIkS7YlYsyMcs +-> ssh-ed25519 dbKeHw nIG5Z+XdJ3dyMxFOxyFMHw5sUkRJ2dsooJbIScNwlxM +brJoiOSQcwgs3vNSk8eK6dzH3zfQGFNdEWj3jjMM5e0 +-> ssh-ed25519 Svnssw +VFbKj457mYT3GXQSacQ13J8MSkYe6A26ssNbqh8LAQ +rJzIG170BcRlsLERhnfaqgRFeAL4Yw7zvtb1gGvUkCU +--- ebIxmIBuNqNgfVWvOJc/0OpFBf3Q7pmApGgHYjrtJI8 +AeO:(7_x0׷ jfV /D.8⿀1ߠ[qf!7ht0Y \ No newline at end of file diff --git a/secrets/darwin-policies-json.age b/secrets/darwin-policies-json.age index 9fa2d2b..eabc269 100644 Binary files a/secrets/darwin-policies-json.age and b/secrets/darwin-policies-json.age differ diff --git a/secrets/network-information.age b/secrets/network-information.age index 0de69b7..bccc467 100644 Binary files a/secrets/network-information.age and b/secrets/network-information.age differ diff --git a/secrets/pihole.age b/secrets/pihole.age index babead9..dfe146e 100644 --- a/secrets/pihole.age +++ b/secrets/pihole.age @@ -1,15 +1,15 @@ age-encryption.org/v1 --> ssh-ed25519 il3lzQ Q+/uqZhUWs5pb5T1ocD+/qTSo4DJbd/W1exruQ34zAE -8HFRvEblGVrkoVaqAl/Af6wrDn6A+3unZIMBipEkwgA --> ssh-ed25519 1g/xww PqXxTvLaF6ZlcVov81VrVH130jFh2iGmHPRtBYV4ME4 -1VBknQzaNZyoz2wvgKX+IZGaOEnJ1xGvxPYxq10ar/U --> ssh-ed25519 +kBihw QXNxY9OQeIM98OqmHoa/S2kMZqSX+ndgxGyCJpHJ+gg -b3DmfUswyPQ09sp57v3QMNEF/Ka3w9Qj2s1kGUSinmQ --> ssh-ed25519 dbKeHw 5GzjKgjUX5e6Net7voWBykC17zRcdSFDFbDsSwp5FAU -GwTEg3YR9HdcQHPg+XjP2Lg1BpcWA4VunbZSBdxVaYU --> ssh-ed25519 Svnssw imRjD5CJu/jOac3t/APHbYBnsyJVQdebR6K52A6GdwM -n+Q9kEEkYRBuEzWlSwbjJNsjF8uKloeUEWYxHa29B4U --> ssh-ed25519 jb0ALQ 4qbGIofHcyhJVfL24peGqqzg0tFdxbWBHJFenwehIAI -Ta3ye4quyHvvE+2CGZwYvQMwWfdrLIdqADLvJYhllPY ---- 3hbht7PYqFafVmcQWQwv3q2gUXM8HXajtmAaMnrh59s - +X984R2,􈱨(#42#*, b禽H_z }߅x7A!))vʞ¨W-eX-G<@~Ek?kGlQK4c&*J9V_0 µz+ɰ¯C ўQGXkg* -jl31JMOE[=S \ No newline at end of file +-> ssh-ed25519 il3lzQ QKUv2QtA6XAVZMc/RET+iJp/IgChWjPnttkT00YNkgo +8wS1EJ6+H+1++dyzEGoq7B7JT7G4wg/NDSNRxDPoRdQ +-> ssh-ed25519 1g/xww I/jn9oDI27fOq7Pf4aMIe10IJUiLz45KQfxbwoV2Yl8 +guK9G+fDLoVxO21YvDeZa14H0gOpm5ma3s+1r7VF77U +-> ssh-ed25519 +kBihw 6uyyp7Jg70FDmlC8Sos+GY/PKPS3QQKR0p1ofODQmC4 +aQDzLv9H54Ucsa3tiVHWhxkV1F83fwNTXIt8k4V5ngs +-> ssh-ed25519 dbKeHw CPQh63MLby86GqOiZv8sxD6qMezQj17fCPLjigCMG0A +OgcvqThhfSUelRy2WZ5eALyJ8uQft8gYdbMuySUi+Ko +-> ssh-ed25519 Svnssw VAK1KKUe7aMf/Rj5r5KnjeobG1JZQXKzNWXjuXpgRyc +Udegl2sZBsVUhN+XwlfSbC1HrKu05uZolm8dsQberuU +-> ssh-ed25519 jb0ALQ M6bx55Kzp4VtQUTq6vkg31JXfew8E+QqHAuXVjFLrxw +wmoYs4tGa56+GuY4r0RtTfXpxW9XTqC2YJlmGsVEHIY +--- wzjCBOS1iGnQe8ZPgaKTs7PZvI0TnRZd11eL7yoaWL0 +$rzGM}(^M؏*lQ̢*U-f7Cc/9~:$ZSR@]htC7y1gaCM !*1B{> oBN& îW_s7&:LK鯵Of׭N1!Vt;QBgRy1j(hv \ No newline at end of file diff --git a/secrets_file.enc b/secrets_file.enc index 20df784..33fcb27 100644 --- a/secrets_file.enc +++ b/secrets_file.enc @@ -1,10 +1,8 @@ $ANSIBLE_VAULT;1.1;AES256 -65366137313461383534313965646333656565353061336361363661613033393264353661346337 -3838653162383134393463323631613439373663396363380a633339396236363962313333343465 -31623961393532666136616438633734366261353866383264323730383432326635626637343739 -3235313062623637380a386235316437396534353261383832643165316565386263396664363962 -62393364333335373631356161373263313930343565626433383539373030363662353630633933 -63336333613965653635313637336437653139616564313861336332323739653865383531356233 -31373530343766343131346663656566363038643230343462336332323135323337353539303763 -33366638393064323431323636346161343936643062323861313766613264336465326132333631 -33306666383561653965303539313366653030663330393363363565333439383133 +33613635643765623937663135313833396162343134383466343966333964386364356134663264 +3137633339396462633431316634623834646437646162360a626564313831373761636161656232 +35316566336232666336646231356665366633303530623961666465366163306166623336656364 +3835353035333031620a633332376237336530343134623832363534383761616564616138363766 +30306361383462353361636161636335313461313835663362393839623735313738316465656537 +66396635323432376530346532353238346139376261366237343763373535623364633731323830 +333730373965613131336166626230333263 diff --git a/secrets_odyssey.enc b/secrets_odyssey.enc index fba7129..a7a96da 100644 --- a/secrets_odyssey.enc +++ b/secrets_odyssey.enc @@ -1,6 +1,9 @@ $ANSIBLE_VAULT;1.1;AES256 -30343638643335363463653231623566623961613534323261393639623865633964653634333562 -3838613035393661656362383736313561366466396439390a383162366362643364636335613664 -39646137666437353762363764373562393736626530333336626261366232383063633732623238 -6531633638366335640a363461383535646663316533386137323966326237373836363561323462 -66646635383137333834363165666365366235333734646364616637383363666239 +61363033383536303833366237323662663236313163663033306138383162383062643830616466 +6531636430613462646161343939343363663533373737340a613433363666353432383463356439 +33656266633131336565613433653062656563656637656464346232656238646339303961373265 +6639643637303433380a393163366331373964353261383662656664643031626432366231346332 +34303964346137616233343930333331306363326332383465653163386539306430303965316437 +30343333373565623431653436653832356366343937653136346535316166383262623730343831 +62376532346237323465653261316339353034323633623632313630666531373839633665333637 +34356162356565396564 diff --git a/systems/darwin/corianne.nix b/systems/darwin/corianne.nix index db34258..582ffdf 100644 --- a/systems/darwin/corianne.nix +++ b/systems/darwin/corianne.nix @@ -15,6 +15,8 @@ in { rig-install ]; + age.secrets.firefox-policy.file = ./../../secrets/darwin-policies-json.age; + # Use a custom configuration.nix location. # $ darwin-rebuild switch -I darwin-config=$HOME/.config/nixpkgs/darwin/configuration.nix environment.darwinConfig = "$HOME/.config/home-manager/configuration.nix"; @@ -74,8 +76,6 @@ in { (sysApp "Logseq") (sysApp "Zed") (sysApp "Steam") - (chromeApp "Instinct Dashboard") - (chromeApp "Carestream") ]; show-process-indicators = true; show-recents = false; @@ -130,6 +130,11 @@ in { --user=${config.system.primaryUser} \ --set-home \ _rig-install ${r-version} + + echo "Applying custom defaults..." + /usr/bin/defaults import \ + /Library/Preferences/org.mozilla.firefox \ + ${config.age.secrets.firefox-policy.path} ''; nix.settings.experimental-features = [ "nix-command" "flakes" ];