Manage data-access container declaratively

This commit is contained in:
Charlotte Van Petegem 2020-12-23 11:52:22 +01:00
parent 45761cb113
commit 565ee07812
No known key found for this signature in database
GPG key ID: 019E764B7184435A
8 changed files with 72 additions and 6 deletions

View file

@ -0,0 +1,23 @@
{ pkgs, ... }: {
imports = [
./config.secret.nix
];
users.users.data = {
isNormalUser = true;
home = "/home/data";
description = "Data Access";
uid = 1000;
group = "users";
};
services.openssh = {
enable = true;
passwordAuthentication = false;
permitRootLogin = "no";
hostKeys = [
{ bits = 4096; path = "/var/secrets/ssh_host_rsa_key"; type = "rsa"; }
{ path = "/var/secrets/ssh_host_ed25519_key"; type = "ed25519"; }
];
};
}