summaryrefslogtreecommitdiff
path: root/modules/nixos/traits/secrets.nix
diff options
context:
space:
mode:
authorseth <[email protected]>2024-10-28 17:12:24 -0400
committerseth <[email protected]>2024-10-28 17:12:24 -0400
commit345c3980708880cefbb8e19b2d1b67c28cd94348 (patch)
treed2f295dd966aa349ba2539a16f81391574aead27 /modules/nixos/traits/secrets.nix
parent51c17b540eb60dbf2974bdabfc1e081e0af1560a (diff)
nixos/secrets: remove support for rootUser
Diffstat (limited to 'modules/nixos/traits/secrets.nix')
-rw-r--r--modules/nixos/traits/secrets.nix12
1 files changed, 0 insertions, 12 deletions
diff --git a/modules/nixos/traits/secrets.nix b/modules/nixos/traits/secrets.nix
index bd685ef..9e0e025 100644
--- a/modules/nixos/traits/secrets.nix
+++ b/modules/nixos/traits/secrets.nix
@@ -12,8 +12,6 @@ in
options.traits.secrets = {
enable = lib.mkEnableOption "secrets management";
- rootUser = lib.mkEnableOption "manage secrets for root user";
-
hostUser = lib.mkEnableOption "manager secrets for host user (see `profiles.server.hostUser`)" // {
default = config.profiles.server.hostUser;
defaultText = "config.profiles.server.hostUser";
@@ -34,16 +32,6 @@ in
};
}
- (lib.mkIf cfg.rootUser {
- age.secrets = {
- rootPassword.file = secretsDir + "/rootPassword.age";
- };
-
- users.users.root = {
- hashedPasswordFile = config.age.secrets.rootPassword.path;
- };
- })
-
(lib.mkIf (config.profiles.server.enable && cfg.hostUser) {
age.secrets = {
userPassword.file = secretsDir + "/userPassword.age";