{inputs, ...}: { flake.nixosModules.sops = {config, ...}: { imports = [inputs.sops-nix.nixosModules.sops]; sops = { age.keyFile = "/etc/sops/age/keys.txt"; defaultSopsFile = ./secrets.yaml; secrets = { gotify-desktop-key = { # Make readable mode = "0444"; }; }; templates = { "gotify-desktop-key".content = config.sops.placeholder.gotify-desktop-key; }; }; # Make the secrets dir readable to normal users systemd.tmpfiles.rules = [ "d /run/secrets 0755 root root -" ]; }; }