Commit graph

20 commits

Author SHA1 Message Date
6dd4431506 drop my own netbox build in favour of nixpkgs 2023-10-12 20:12:22 +00:00
983941331d ops/vault: add nixbuild to clouvider-lon01 2023-05-07 14:39:17 +01:00
7fe7452e2f ops/nixos: add tumblrandom 2023-04-18 20:05:51 +00:00
4daa3a593a nixbuild-distributed: create 2023-03-09 21:33:42 +00:00
08d59f4e20 ops/vault: create binary-cache-deployer 2023-02-25 22:16:56 +00:00
77c4d9d7c2 totoro: ADSB 2023-01-09 02:09:04 +00:00
653ac8f5f0 updateplexpass: use Plex Pass key to fetch new versions 2023-01-08 01:54:22 +00:00
97d71c78a1 ops/vault: add authentik-backed auth 2022-05-21 15:42:55 +01:00
13d51a7978 ops/nixos: move gitlab-runner registration token to vault 2022-05-13 21:45:36 +00:00
bf601faa89 nix/pkgs/authentik: init 2022-05-12 22:55:10 +00:00
dca96efffe fup: move config to secret 2022-04-10 01:37:37 +01:00
8647af22d7 ops/nixos: put more things in Vault 2022-04-09 21:51:24 +01:00
2536214734 deluge: migrate auth file to vault 2022-04-09 20:59:11 +01:00
97a2e46eeb lukegbcom: autodeploy using Vault 2022-04-05 22:04:32 +01:00
dbaabf1295 vault: deployer should be allowed to read nix-daemon secrets 2022-03-24 22:20:44 +00:00
7592e76a31 tokend: init
tokend is responsible for issuing service-scoped tokens based on the token held
and generated by the Vault Agent.

It can also generate "server-user" scoped tokens, which exist for convenience's
sake: they are not a strong attestation of the user on the machine, and have
limited privileges compared to a Vault token issued using e.g. `vault login
-method=oidc`.
2022-03-20 17:47:52 +00:00
148e071c21 ops/vault/cfg: add acme-ca 2022-03-16 00:18:47 +00:00
fb7e18260a ops/vault/cfg: where we're going, we don't need secrets.nix 2022-03-16 00:06:46 +00:00
23df8e3b18 ops/vault/cfg: initial configuration 2022-03-14 23:34:33 +00:00
92998b5d36 ops/vault/cfg: init terranix stuff 2022-03-14 21:29:15 +00:00