about summary refs log tree commit diff
path: root/modules/services
diff options
context:
space:
mode:
authorFranck Cuny <franck@fcuny.net>2022-07-18 17:33:26 -0700
committerFranck Cuny <franck@fcuny.net>2022-07-18 17:34:55 -0700
commit3f670b25133e929d8a6be2aff6ae648ee18f81a2 (patch)
tree35d5323d57233277e1e106b4981204ca3483295d /modules/services
parentfix(modules/backup): reduce verbosity for restic (diff)
downloadworld-3f670b25133e929d8a6be2aff6ae648ee18f81a2.tar.gz
feat(modules/gerrit): manage secure configuration with nix
Currently the secure configuration for gerrit is not managed by nix.
This is likely going to break in the future and I'll hate myself for
that. Let's move it into nix and encrypt it with age, like we do for
other secrets.

Change-Id: Ia7a006748a3ad64fa4b97ca9e8cbd98c99433982
Reviewed-on: https://cl.fcuny.net/c/world/+/622
Tested-by: CI
Reviewed-by: Franck Cuny <franck@fcuny.net>
Diffstat (limited to 'modules/services')
-rw-r--r--modules/services/gerrit/default.nix1
1 files changed, 1 insertions, 0 deletions
diff --git a/modules/services/gerrit/default.nix b/modules/services/gerrit/default.nix
index 9ae9e50..1592839 100644
--- a/modules/services/gerrit/default.nix
+++ b/modules/services/gerrit/default.nix
@@ -1,6 +1,7 @@
 { config, pkgs, lib, ... }:
 let
   cfg = config.my.services.gerrit;
+  secrets = config.age.secrets;
 
   my-gerrit-hook = name:
     pkgs.writeShellScript "my-gerrit-hook" ''