stockholm/lass/5pkgs/l-gen-secrets/default.nix

58 lines
1.7 KiB
Nix
Raw Normal View History

2018-04-05 15:44:34 +00:00
{ pkgs }:
2018-04-21 10:42:30 +00:00
pkgs.writeDashBin "l-gen-secrets" ''
2018-04-05 15:44:34 +00:00
HOSTNAME="$1"
TMPDIR=$(${pkgs.coreutils}/bin/mktemp -d)
PASSWORD=$(${pkgs.pwgen}/bin/pwgen 25 1)
HASHED_PASSWORD=$(echo $PASSWORD | ${pkgs.hashPassword}/bin/hashPassword -s) > /dev/null
${pkgs.openssh}/bin/ssh-keygen -t ed25519 -f $TMPDIR/ssh.id_ed25519 -P "" -C "" >/dev/null
${pkgs.openssl}/bin/openssl genrsa -out $TMPDIR/retiolum.rsa_key.priv 4096 2>/dev/null > /dev/null
${pkgs.openssl}/bin/openssl rsa -in $TMPDIR/retiolum.rsa_key.priv -pubout -out $TMPDIR/retiolum.rsa_key.pub 2>/dev/null > /dev/null
2022-03-23 14:20:01 +00:00
${pkgs.wireguard-tools}/bin/wg genkey > $TMPDIR/wiregrill.key
${pkgs.coreutils}/bin/cat $TMPDIR/wiregrill.key | ${pkgs.wireguard-tools}/bin/wg pubkey > $TMPDIR/wiregrill.pub
2018-04-05 15:44:34 +00:00
cat <<EOF > $TMPDIR/hashedPasswords.nix
{
root = "$HASHED_PASSWORD";
mainUser = "$HASHED_PASSWORD";
}
EOF
cd $TMPDIR
for x in *; do
2018-05-16 15:32:29 +00:00
${pkgs.coreutils}/bin/cat $x | ${pkgs.pass}/bin/pass insert -m hosts/$HOSTNAME/$x > /dev/null
2018-04-05 15:44:34 +00:00
done
2018-05-16 15:32:29 +00:00
echo $PASSWORD | ${pkgs.pass}/bin/pass insert -m admin/$HOSTNAME/pass > /dev/null
2018-04-05 15:44:34 +00:00
cat <<EOF
$HOSTNAME = {
cores = 1;
nets = {
retiolum = {
ip4.addr = "10.243.0.changeme";
2021-01-24 08:49:20 +00:00
ip6.addr = r6 "changeme";
2018-04-05 15:44:34 +00:00
aliases = [
"$HOSTNAME.r"
];
tinc.pubkey = ${"''"}
$(cat $TMPDIR/retiolum.rsa_key.pub)
${"''"};
};
2018-12-16 15:11:02 +00:00
wiregrill = {
2021-01-24 08:49:20 +00:00
ip6.addr = w6 "changeme";
2018-12-09 16:26:41 +00:00
aliases = [
"$HOSTNAME.w"
];
wireguard.pubkey = ${"''"}
2018-12-16 15:11:02 +00:00
$(cat $TMPDIR/wiregrill.pub)
2018-12-09 16:26:41 +00:00
${"''"};
};
2018-04-05 15:44:34 +00:00
};
ssh.privkey.path = <secrets/ssh.id_ed25519>;
ssh.pubkey = "$(cat $TMPDIR/ssh.id_ed25519.pub)";
};
EOF
rm -rf $TMPDIR
''