commit 305809514be066b9f2e9977071f375df25c0c301 Author: Jacob Hinkle Date: Tue Aug 30 12:03:42 2022 -0400 Add .sops.yaml and secrets.yaml diff --git a/.sops.yaml b/.sops.yaml new file mode 100644 index 0000000..770b112 --- /dev/null +++ b/.sops.yaml @@ -0,0 +1,17 @@ +# This example uses YAML anchors which allows reuse of multiple keys +# without having to repeat yourself. +# Also see https://github.com/Mic92/dotfiles/blob/master/nixos/.sops.yaml +# for a more complex example. +keys: + - &admin_jacob_pedro age16k5tturaeszpxugxawmfsxkrce2cfvp06s00eaxcee243anu4qysnjfr70 + - &server_pedro age1nakx3lrrazwkndf5k5cm9pcv4028tpwfyevhfet4xlkcqyfryvhs22zgaf + - &admin_jacob_buck age1u8nv4862y2emwmltnhgnjj38vm3khp9ay7frp36aecln64duygmqnw5423 + - &server_buck age1lu45e0mecnq6hh5c9muhr38pw7832xflnnj30e3c5kdy9typqd6sckh4gm +creation_rules: + - path_regex: secrets.yaml$ + key_groups: + - age: + - *admin_jacob_pedro + - *server_pedro + - *admin_jacob_buck + - *server_buck diff --git a/secrets.yaml b/secrets.yaml new file mode 100644 index 0000000..2216399 --- /dev/null +++ b/secrets.yaml @@ -0,0 +1,61 @@ +email: + gmail: + address: ENC[AES256_GCM,data:uWVgCX2nTVJn8HlEMKfU86DsVG9c0A==,iv:uLJk521DET65fizoUUKnLB325fNmSZNc3M9tNqjq2qg=,tag:zSlTWP3VYu0JR0FH0gdCHw==,type:str] + password: ENC[AES256_GCM,data:DKB+h3jaX+BP,iv:kdc1NcYVLie3TRCf2qq5x8V3WaSKXKKHDqBDzjpQMDw=,tag:P1mmaKhPcX1yMUxI5I/uXA==,type:str] + jhink: + address: ENC[AES256_GCM,data:nIuL4Ay343z3lzjiXKnSqPLsqZR96w==,iv:iKQCw/cj70q2Afuf97g3njkEcD5ux4HquXFTZ5K7xHo=,tag:BsnLC1MspQOsMN6qxtY4uQ==,type:str] + password: ENC[AES256_GCM,data:/F+gn/TaRqX+,iv:y6aNJb1zG+plXwcKilQLVFEnlemDJUV0PyIicbAD6BU=,tag:A2KPxqB4xZ2erFA/nstovg==,type:str] +pihole: + webpassword: ENC[AES256_GCM,data:bqBbGE5M4LUukMh7vQA=,iv:YhKaO2WQq5Ar9aKitgRTbDU2Ld2Cdc0wmrcQZ92lztY=,tag:UGnerGhtQBjO+n4LobdSyg==,type:str] +spotify: + username: ENC[AES256_GCM,data:EXLRJXrHsP+k,iv:5pvHLVnrtG+oZEPZsBY/4/+b9QQEBTT7jiPvmkBHAWY=,tag:gcCJqgBd7b2+e2k0oIVY8w==,type:str] + password: ENC[AES256_GCM,data:DHj06DfPU98C,iv:wxinj4sLt8rQ6hW4NtxIHQPnAJ3acXRXQHRsRaoiGR8=,tag:b7ota0m1gpwSZYSDY1Uj+A==,type:str] +wifi: + env: ENC[AES256_GCM,data:cgalQMWa9+d3JFozSSbw//hu/8jZPqBhlSSHFAaLxVmEi5xPDSMJwO1Savw=,iv:nmYeB+Ksh7L5g51J7kbrtyPaAosqHtcyMbxyQ2ArfNE=,tag:AvGxOJftp0WU1WyhCdLYiw==,type:str] +sops: + kms: [] + gcp_kms: [] + azure_kv: [] + hc_vault: [] + age: + - recipient: age16k5tturaeszpxugxawmfsxkrce2cfvp06s00eaxcee243anu4qysnjfr70 + enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSB3WUdLR3JGeXZ6VDNUNkx6 + ZThRWmw4TksxYU5Qbm4zZ1VKYzJ3ZGt5SFJjCmY0K0xxaVlISGZOWXM1SkhkdEZ5 + S0xQdnNSck9sTGZkRTc4amp4Wk91bE0KLS0tICtqQzMyZjE2MWJuNC9LQVZqc25z + blczWVI3TllZSitsODY2cEU3NzV1dG8KNX7bqz8gTx8FspxTOgcloJ33Xe+J1/5S + FafQ+kfHi/TKbNHI2E4cADMf2CgT7g6+8QN8UZIsGXcUONUgQZ9K6A== + -----END AGE ENCRYPTED FILE----- + - recipient: age1nakx3lrrazwkndf5k5cm9pcv4028tpwfyevhfet4xlkcqyfryvhs22zgaf + enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBxNENFb0xXZXVxdHhpYWdx + c1QxRXFadEFzczFvWFhjOWE0dlh0b3l0WHpVCkV4OEVMdFZaTW9oaUxFUE91aDMx + SVdyMG1KSTJJdGRVL2VXa1JkK3lCc3cKLS0tIGpzNmpacEwreDBFdUg3ZTd2amo4 + TjFmVVdkalorOGwxei82RFZqb0pkbmMKQq25keRziS7oGDktNYyEIRIPLygtYku8 + kIyK1sDwbmiFY+Se96twbVJt0vH+FFLc8IPeVDfAyANxYqIYJMwmdg== + -----END AGE ENCRYPTED FILE----- + - recipient: age1u8nv4862y2emwmltnhgnjj38vm3khp9ay7frp36aecln64duygmqnw5423 + enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBnZmpjQytTcHkyYXBtQWh5 + QThoRWgxZ1hFTThnbTg5V3dxdEpoV2cxUmlRCm5iK1JMVG5hUklNQzlIdlN1b2ha + cmZVR0ZBcTd1K1FETVBwWUZHWlluOVEKLS0tIHIzSDRza05HdzVMSFhHc2pwdkJw + TGpYTXJoSXM5UlJYczVjcFJNL3NqeHMKKcXwWb/sNyn2u0hhBK2sWYR3zJjCeAck + zTGA/jy9t4aGyIuPYL1PsSc/5WLsry1tAq4J0h0rKywD0sSocV8QDw== + -----END AGE ENCRYPTED FILE----- + - recipient: age1lu45e0mecnq6hh5c9muhr38pw7832xflnnj30e3c5kdy9typqd6sckh4gm + enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBpSmlGWUU0Sll4d2p3Yy9m + Ynp1bVRhUDBnZEt0cmlDNCtwT1oyclJ1M0JRCkFITHdvaExBYWRVR0YvcWQvUlo5 + Q1p1bEZvOVJEcWNIZ242N1YyeDBLWnMKLS0tIEtiTmJFaVQybTExcnNOL2VyV1BN + WVUwaEIwWTFFTExyT3hLSC9wODhJdGcKWsNIUsT06qYA9vUVeFHQrCdcn2MkHt+w + Rr7W+4uaNb8Qxo/NUp9kodE9m/fg9XVd8wM7HUP4wJC0rE4GSnFvGg== + -----END AGE ENCRYPTED FILE----- + lastmodified: "2022-08-30T16:00:02Z" + mac: ENC[AES256_GCM,data:P1BZ7ba0yYAYyPWwJRFSJrDiXY+ETAeFIhOTTSC7acZItawZA3n39iAS4hzI4CP/Jse4bOnohmtz+3s83dNWAVhuQvJ6ys9996xayt5KDMkCmaN+53ve5R6ySivXCl31/yWsExo4kF6qF8rptwnF2QpVzZJHQlDmr1mJO4yrxRo=,iv:V6ejyfpOrGTX3wI1KOtqkgcccGNxOT1MJFlAA1DhfuQ=,tag:ShAMQdK+DiGwrrrvBlDiNA==,type:str] + pgp: [] + unencrypted_suffix: _unencrypted + version: 3.7.3