diff --git a/modules/features/gotify-desktop/default.nix b/modules/features/gotify-desktop/default.nix index fb6b37a..01e124c 100644 --- a/modules/features/gotify-desktop/default.nix +++ b/modules/features/gotify-desktop/default.nix @@ -18,7 +18,7 @@ config-file = pkgs.writeText "config.toml" '' [gotify] url = "wss://ntfy.voidarc.co.uk:443" - token = { command = "cat /run/secrets/gotify-desktop-key.txt"} + token = { command = "cat /run/secrets/gotify-desktop-key"} [notification] min_priority = 1 ''; diff --git a/modules/features/sops/default.nix b/modules/features/sops/default.nix index 6b21ef8..b2919bd 100644 --- a/modules/features/sops/default.nix +++ b/modules/features/sops/default.nix @@ -1,8 +1,4 @@ -{ - self, - inputs, - ... -}: { +{inputs, ...}: { flake.nixosModules.sops = {config, ...}: { imports = [inputs.sops-nix.nixosModules.sops]; @@ -12,12 +8,17 @@ secrets = { gotify-desktop-key = { - path = "/run/secrets/gotify-desktop-key.txt"; + # Make readable + mode = "0444"; }; }; templates = { - "gotify-desktop-key" = config.sops.placeholder.gotify-desktop-key; + "gotify-desktop-key".content = config.sops.placeholder.gotify-desktop-key; }; }; + # Make the secrets dir readable to normal users + systemd.tmpfiles.rules = [ + "d /run/secrets 0755 root root -" + ]; }; }