stan: use default kernel, add main secrets file

This commit is contained in:
Aaron Bieber 2022-09-12 13:20:43 -06:00
parent 7f91e1e2b0
commit ded434c205
No known key found for this signature in database

View File

@ -29,7 +29,7 @@ in {
"/crypto_keyfile.bin";
secrets = { "/crypto_keyfile.bin" = null; };
};
kernelPackages = pkgs.linuxPackages_latest;
kernelPackages = pkgs.linuxPackages;
kernelParams = [ "intel_idle.max_cstate=4" ];
};
@ -64,6 +64,12 @@ in {
owner = "root";
mode = "400";
};
vm_pass = {
sopsFile = config.xin-secrets.stan.main;
owner = "root";
group = "wheel";
mode = "400";
};
peerix_private_key = {
sopsFile = config.xin-secrets.stan.peerix;
owner = "${peerixUser}";