cluster/services/idm: use cluster secrets

This commit is contained in:
Max Headroom 2024-07-08 18:41:51 +02:00
parent deaa423c86
commit 7b95308f0d
8 changed files with 5 additions and 3 deletions

View file

@ -5,10 +5,8 @@ let
in in
{ {
age.secrets.idmServiceAccountCredentials.file = ./secrets/service-account-${config.networking.hostName}.age;
systemd.services.kanidm-unixd.serviceConfig = { systemd.services.kanidm-unixd.serviceConfig = {
EnvironmentFile = config.age.secrets.idmServiceAccountCredentials.path; EnvironmentFile = cluster.config.services.idm.secrets.serviceAccountCredentials.path;
}; };
services.kanidm = { services.kanidm = {

View file

@ -33,6 +33,10 @@
./policies/soda.nix ./policies/soda.nix
]; ];
}; };
secrets.serviceAccountCredentials = {
nodes = config.services.idm.nodes.client;
shared = false;
};
}; };
dns.records = let dns.records = let