infrastructure stuff
surtur
d125d70562
* set up global secrets (sops) * import common network (lan/tailscale) settings in pertinent places * use common coredns module for both nixpi and loki |
||
---|---|---|
ansible | ||
nix | ||
.envrc | ||
.gitattributes | ||
.gitignore | ||
.terraform.lock.hcl | ||
main.tf | ||
README.md | ||
tailscale.tf | ||
terraform.tf | ||
variables.tf |
infra
this repo holds the code describing my very own infra (machines I use/manage) and is very much a WIP.
NixOS configurations are present in the ./nix
folder.
should contain zero secrets, except encrypted either with age
,
sops-nix
, or ansible-vault
.
terraform
secrets are supplied as ENV vars at runtime by sourcing the
decrypted infra-vars
file (stationed in its place with home-manager
)
using direnv
.