From 5c35057799c85e2927b38fd6b70378c95725414e Mon Sep 17 00:00:00 2001 From: Ryan Lahfa Date: Tue, 13 Feb 2024 18:43:39 +0100 Subject: [PATCH] admins: enroll bensmrs Signed-off-by: Ryan Lahfa --- profiles/sysadmin.nix | 1 + pubkeys/bensmrs.keys | 1 + secrets/matrix-shared-secret.age | Bin 893 -> 1605 bytes secrets/mautrix-telegram.age | Bin 1205 -> 1917 bytes secrets/secrets.nix | 7 ++++--- secrets/vaultwarden-secrets.age | Bin 877 -> 1589 bytes 6 files changed, 6 insertions(+), 3 deletions(-) create mode 100644 pubkeys/bensmrs.keys diff --git a/profiles/sysadmin.nix b/profiles/sysadmin.nix index 965b5ee..d02b24f 100644 --- a/profiles/sysadmin.nix +++ b/profiles/sysadmin.nix @@ -1,6 +1,7 @@ { pkgs, ... }: { users.users.root.openssh.authorizedKeys.keyFiles = [ ../pubkeys/raito.keys + ../pubkeys/bensmrs.keys ]; environment.systemPackages = [ diff --git a/pubkeys/bensmrs.keys b/pubkeys/bensmrs.keys new file mode 100644 index 0000000..4dda9d1 --- /dev/null +++ b/pubkeys/bensmrs.keys @@ -0,0 +1 @@ +ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQC0kAxg8WC4X+nU8poDNs1Gac9+GjFMJh9La0D17iryJQZKdlNlpe82LnqC9CwcBzfzzT9XMrnZDajcRe16SLwK1HpIgIUQr/8g5CAgmj+/n63i86lc2/fTrgJh1sjJFC+6DEWfle4OmbiM5smKNZhh6HhUcCYL0vNI0bpIB5OgJgR0NTHeZ+Vs6tNx1TOHUXyFxeyfcFtSpwk06xA8667s44N/obEw/H4cm/sXcFx9s7G+40FT2M2E3XvT7r05kBOGptsumW2pSl8FzT4gOeOonc/A15huKnT47ORFTPhbO0OCcTpDbPQLfLpHeCrb/f1kdbRPzdz02spgDmATjQr93KtANV+UJQn5j+/qxRXquHPvPRWxfcCFerpMGai7X5IfgTVBE5TWT8MmjxaqhBk6vpMUA+hz/VwDFDhWJVzLHdp/S/mWoUKU/W3vH8bOKEpVBbtj7hxOia52TMfv1psC4217OGKQ4sYeXs8kMzXM5gGl29HKpuUU8ike2c8jSCSjWaEAE7ZdsDfuor35zjRBp40z4z4toSZYKJyzNUeMclKHXGy7DLfED5OTkMy7Kd3IIcHq/1PwnAKlxEXXP6k53Ya1pRPx4We61aNOGNRIC1DBKDjmzrv/IKXtf+/6+M3lZqT8wNnoK0+2U+bvkoRrEYtB+E3RQDfGW+Mm4/sAsw== diff --git a/secrets/matrix-shared-secret.age b/secrets/matrix-shared-secret.age index 793750b810c2bde705bd069486d6ecb3168f9f9a..a5f248562e466af464c743d1dae28f5f5aa9c8b1 100644 GIT binary patch literal 1605 zcmZ9KJ;?k90miMMLN=jv5QKM75#!r@Cl`@IzLUFrUXn|4|DojjJGsjxxg-U_K`B-o z+(eOfsNh;uEG|wWqKgU+QXJ}{C@xYF5qvxR7l&tke(?OBFi#)TE*{p)SoYn^{g6X5 z0zAI*aJvJo>b{j1tH85uX=_xv=|a4Cnqq?+(Ja$hYiLThG>&yk_^g1<5Wu_hRE817(&`T5539k!&q*%hn6KK7uFaD5&45(O;l(&0f&Rr<{v zWwzz)#X>{>!VMB>K?l>1D3?5L!-QkHRS?F0tu&d91JPPoqTO}C#gQOnNMsL=sKpIv z&MXYghAz5xBC?&T=gy`!X(op$-|Or3WE&fc6ZSpruv7ZuB{zF8msa5GPKJeoqpQ#CeG{%|tM~Dh*2lsKU`~_h{3gMt6zn9Jxhxl0RSj zxm#$yTe0drj+39up4p4J(&`d18`4Sh> zC~LyHf+RJj2lt(kl{q%p*xFELv9JH11|Mn4WF9KI0~bRwM!3Hh(hwOe%5h6R=NuJa#^z<#AdCvqgON>T+;_dksc8iQ~;l>0LbBxnIa$t>wg`ArBxaY*Un0 z5s35g;7<#mh0V0=e39_>-iQ5dY!OuUYn!c*106v=hf8C*JmWa>cradbWK7j(In-0}`Tp4VnGP^$KmF8#~@9&9(7D%cQn*<2M3eHq0U^g#IDMm3tbDALYVV_t1IhP{s2u$g!BNe5`Ml^oP`htM_ngD+_ad929Al96^* z$vqq4c^Z+semcg$Q`{GY$QRet>!pL+M_fBw;nUw9FC_1!ny7ao!i{_@>#{`-Zm49}8xnBlMA zd;Py(`@u(Edad}w7yoYGgSUV8>G%HhI*@+s+s)hWyz#5AYVZH?hi`q^&HmXjKl#UZ uzH$8R%kuY`PbLcZ>^I%3pa1=@cRzmPgEv2;IG_F5FF*0E=}Vvc`2PS0NgXHv literal 893 zcmZ9Jz02Hm0D%3dAQ^;8r&8raboqHEm(M$tVlE$d`M6w?HB-Z#l5xm=Q^ zlMb~*2f;<`A`V(mR|{_u6?7?14lZ3paIiX9gjYnnyo-Oq!}C0D6bysRE4!jj^6b^T zjNoPj4X+NWDjo(tN)V&TVAk@aLk~vPOrWiiyp20UmL*cFe5|m`t~QoMJ>IT4pR$fU z+pgvwR1`adl9-*Ln|O*59CGkve$l4cJ~$B+qpdAHPA8oRobfrWtlU9bT8ykgoHJu1 z^C+1&mePqDGD88N^*x@sh=r>y9c?fTn4G-IbyQeKcB+>)AB7d-0i}(Y8MG}7*(<@O zNr=YUs6jI>ilXLwYy$GBFwu^Js?e9&*ei&+8m{uf z40vl9ltPfX{85K%o0*2#PA5(23*iH45hdZGjqyd zzOS`*7L4%uQSZhco1bJ<6i@va2|(jF=`Pk}wb_VlhwUf_V_e}5WumAa7c;UUDuAE+a>xs+vF5Y(EeJb4k^$>aI?f&sQ zS5)-s{Zj z*Y<)UI?XobL#7*JDr^(Y*dAX(z_^S-2r}d)fdoMr*~m13u_a6~n=Im@_``njFZd+i z&nI8m)ED)M8fN~~_9l0Ep$X0Mz~a{yqR3j*wL-C&FE0>jqa;-pB0@Ri9i6PQRDsYSm@a~s4`GJ(GSStAcv{-Ic<-yqUiFa zFszevFL#v|M)JZa9MmWlm`54i?hOY-tRjIjN?i&J2XGqt^`R^yU>X%=ES7X*YTGzW zbC(Cq1l|TI3XX5knG%^Smv1^I(R6C5JZn1&Kd=lr8JEdq zhNpU^Y53Eeo2gVB184=xtb$aW2HjNG2A+Upc#UoeVA!vk9l@K+uvN3ld^&K)Jq8}r zWpZw02H_ws+>><~5Nc*$w818oXsE0NV%)`Dq(!8B#WqSKwJl2B)~MuU)k>*J#x`R? zv$!_}r?E;&L_Z{f`9SlSnahxaaWI@R1J-LMig|VIt8SrL!m8|oNApq2%$fr^^4e`I zAFKIlY0MFBl?o6ltSQ4FLLsGN*dzcGh)GWDPH&VF1SZP3OF~^{j?;&aEhJ(CHmpw~b+8|~q4$F28S#1I9u&@u8AuPy=+Qx|gy zT1XQ(u!}8aW?_@wxA_wSEFbOnTYc? zoz=#4|TBuMDql#tGcJU^SH!MroD(r zjY2b*O((QbjYe_}&tp1bPJ{%?%T!p_X;Pmw^tjQb;syx=gikxVty`*Ysv#!dKiPF*Sz88%hkJAf7II4GZ0?v3@MH~T0vBg&*6LJPVMN~64z`FgZ zAWRxg7fMAJtW0XS(Knr}hE+($V&Y*aInDXXgKr{2ksR?Iw@ z>9RFrnO>n6*-+YJuttVtZa(qsk)n9K$JJ@XHmgN$2DCJ+t)on_p~WQ)pAc?&B&z~b zC$sjvlWT^(ip%!Pc#9V5ZFXD&$r+EfiU}rie1*|X3kXG|(_zsuJyEf~FcUZqvr#N^ zhH7o#rEzGErRt|2;m!2~SX^9O=uQldE3ga`5`4a!2^=i(U>O-s8}L{Sg-*;@Tmz46 zK0tuw{p;U(;NbRs-Vgrv{Yy*R_PqHW<@qb`_G{~m*Eb)E2j^BFx@*lJ`_M<&_KT|z z>@^ZOp0ZhtQN`yJt}&uta|l&!t{p-X?bU%U9! zsT;=G<(2Hgb4NaOJ~^>XJ^S$K>n<1e?0vHJ#0%GL+#P(G3$IFMWS^xQ?%LniM7kR1i+k1X^an;*r-(Hx0=q}Tf z2d=DL_r^8j-Oqq8@7VYHjY~-G$G@&W&VKWWJH%V=Kf_k(TfemGmAH{GzXD`{?<@4EcSLGrJUZu-s5dvE`G?lWh8^6YIN?EmReZ}q81*BsE9h ze(di2?A3F7;}0HNvHBSTdH2T6=U-WRZ_TOmgV*+~d2Rm4##i?&tqJZ`MjK9U*mObr W(SO#zRsQ)~$KYP^Yitt*007{@h>ixAkT6DqkqslSqv`Y7)#3EowRi3AdcC#1_R90_+UvDzyN2CJ%W80s$l_8UqU(AYp_U4T=hi!@0#U#28czpb;>F;(%;`em}lPji;vXSX!$@ zi3E;f5J475lQm4F36dsJs}PH^S$ClV2uiN%)FN&a$s4?oPt7P9r3!;!kPPxLgH>`0 z9|u$d=drj}%_Ie{hyiF-H5fZuWSKXXWV%Ht#XKlspz-duP(&kLLe*EX@>DUKi`i?8 z7_z9m7?5zrCnutA*&3uFzfcjlu7HR;Il`F?n~9vI5V9FiOCIA&BoC8r!V0?mF0&p= zaFJrEkTFZqgfF3|0FC#hMAT7+6t>&cRq`@zCds5CV6( zS_}yz>0HT4LX@=(VT#0c+2ULPvhu7xr}ZzyYmVH zAbDBSfiz27q*7SKNlZ~;Kt}ROI+BH0P9anzREavG5N6?N|gHBxwWF1wxl%*Au!^5ZePC+nGxH}G- zNjPbyT|v7KZDZkZh$yxJoe;^{LAJswMJ(x*y(+b9_0;BCspyf*E>MnAbl9Rf3Q0>q zHb;>>kwgSF%6EwhkybK{qFM6>Th&Lipc1KCifO@D)XE8Wx~O-T5L#gYDvi_rV5|*h zzzhQ!j7DRNF7n-vZoMq+ZpW`iKwq`6et$zfcKK~sKHEg1K5Aqzto7R|cfGyBmjsDcn;sVk&=c5I$_AM%}cXe4$ z&wl<+tL4CwE8TPV8Lh^5u09yq{odH=`Rg`3ZdmjvkB;1)GoNWabarar`pshe;GI=X z7dH(L21Z|>y;ZW+uFV)|A9-VZ#go?K#^F78Cwl9*JrPFV>}`K>vitD$P4AwxHa`8< zKaRgXg_n-Jyo=gr?3nw(jD>v8b6>*+CdF23|D2zRy|ig5S7s(rfxs((dZxh!+j z{`+T$zNdZiH);DEX8#a=Ry^7Y?#m7II983H`=M^yMuTs7+1RS4ne%v(q_RY2HT=2TlGYd8EPWZ|B%5M2abN#@{B@;W2 zjQ7v{apkRlpFOaIYX9(a&;6DKTk)Yz+rZ4hgBy<%$I7Rc_agC2FC=y}ubz&cX}-Mi m`ia8CAJ`YCB*))>K5XE>mJ)le99cVtd7k>EdHBgN?e diff --git a/secrets/secrets.nix b/secrets/secrets.nix index 63cb505..6303af9 100644 --- a/secrets/secrets.nix +++ b/secrets/secrets.nix @@ -5,10 +5,11 @@ let lagon = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIN8fiqJw9RvVVQghG0OVKsXAkBcWox4JsozfxToLAiIK root@lagon"; # Add yourself. raito = readKeyFile ../pubkeys/raito.keys; + bensmrs = readKeyFile ../pubkeys/bensmrs.keys; - matrix-admins = raito; - vaultwarden-admins = raito; - keycloak-admins = raito; + matrix-admins = raito ++ bensmrs; + vaultwarden-admins = raito ++ bensmrs; + keycloak-admins = raito ++ bensmrs; in { "matrix-shared-secret.age".publicKeys = [ estragon ] ++ matrix-admins; diff --git a/secrets/vaultwarden-secrets.age b/secrets/vaultwarden-secrets.age index ba8875475a80daee531f299a1f48a6f87fd75f72..c237fa541071d1a37c3e80a8c56163479c00477a 100644 GIT binary patch literal 1589 zcmZ9KyUYCs0fvi<5`G{QJGjWVsT@9YzoAreKRHQGPLh+HBu=>}C->_)NgdR|K}9H) zA}&I~#YIIaj$##&VzF)x-CSIRE|tg zzWgwb`C}3zI1bYf$_+=A+k?a74WgnFQy&(Q6tvKBjkO^1qs7ueI{N6^8q-CttIY-m z|W=h>^1T8bI0WrQ&a9b^|wdBI~bJ{Ql59M&-R0CMXRuCc)&2~hS zW|2j?ax$2z<_sI+Dv^gcJ6)G5ABr*uru)s6uqA9Q%GH# zXSA$w0k!Y6q3gz|LhzhKyKP|A+A~i2V$L8=Q9J^3k$$EtwgoJ?Dw8utr zr*kXH9y8B{uNqOIhpm#%(5~tv5~PiV*0-3!SXj1!@NSWou|Ku)T@R-M+lEWe9!eKt z6)!V3X5sPidSxdz6&q@YG!z-;_o?z3g73{_W`Hw6u{^bs+SCwCVVSNd%1ZWp?dRWu z%gu<42MM|u(S>I)3nj_$>>Mldm|D8D9ld0?puK>_Q?>5E*tr2k>|ofqT`VasK~oy( zr0tE+pI2`Hdvc=Lx(P1m0^U92|7nm(lPBguMjc)*jj@cXxHPrZp6qN^q5ZaXxDIdF zqF5qY?7W$=ffXkLjcj0bD9jKms@CJ4TCl~waZX&fccnwp@OOHhZ0$Mi(~_?0PN;4` zKBOGhANaw6rdbzgGGS9H;zgD@`u%-l`)pIvn;QF7dC`e6Ob>>%U~N1_BFZoCHdI3&*~e#g@5iQIcTZWVV6$xbGYDfn_=ihu#^12JX( z5nH75?DOU<^h`F7aLJ0kLl1|XHB_ACQ@kRZ?cLlyKQkf0~%f^dU1 zv#bqePCV^T)RT%3yIhIvI9}wz#Tn&tXqP+DtbD-J3DsxFyg5;LC;)G3)-8d0w^*fH zXX>MD24Y%<_Hd`peGR3~yy#`uh!-8v1bS2X%M}%wvkY=DiTl+?YMRZik%2UO%|X%7Qq*AGfH7##&bf*Q%=e(Hl3fy` z?wCG}cZqQHQg6JSy*0eCIjzgs#IL?F;;J6YSczzAKpp{wUk40cEhUSniR?bI^T;KymsMuZzv(+ zW5Gm5ij&*|1+&Hr65$SrE`<;Ih2lP?nJZ5r1*=p9r8eu1cn2p>v5p;)UBJU?rM{4| zGC$L9n$M&n0FRH44?}Z3j5KXD{76KX;yyuwAT}%KF?F=Nolpc!Po;@S#8d)b{jRu|8cFZjUsyMkdaOxLJ6oOW4y zCqob~`&jR_&hfbIg~5O%`*cUD$e~nqz(Og)FpHCkzxC<_r`w9MgL)#yYQC*(j^J};>5`Koh*NUGhBlW-5+yp&ZcckBipuCpL&sHTk8EzCVS0%+ zxdsYJj(89HJ|eYBC?s>javWWvXylhXn8w4QU7J9c10zw!5!adyx01VUGsm_WHeNNH$xKC%I~+#4$^;+hAsmnHh*`M_GbR!Rtw~*JQ8*K1SsW;mFoS_ps2X zmY_AjEuz%#+iD!Pu!Lw3c70iBXuVMavdQq%ajz1{jbeG@9s?X(?NF2?g+{New)CPY z5e|rWS&OU5kngvAzSn2*+Uzb@DqSykxF}yR^UbQ^Sc98KDWWlzWhD^u<`T?#xMzha z7;|fQRr~5KURK&#>p&IBgo!vK4+CQ|OURrCLhhdwN~sbtr3fdQXJl)-j)29$Z3S-N zO|1p1mAmnlZ3tyE#+U0|svyxbmm?iO-Hrq8d5zF%YRPmGnQ{Ne47wEGX=di#Z^z`y+bkI$HAf8Tg^@8vIEdAGTK zUwWkeMf~{7t+UHJfBtap{_326^V^%(w*TFJv3KLalLw#NecJjz-FoBk>&D%WUw!}E GFaHNkoiI57