meaning reencrypt shared secrets to the new key... also, make use of nixos-hardware's module for t14
* set up global secrets (sops) * import common network (lan/tailscale) settings in pertinent places * use common coredns module for both nixpi and loki