cluster/services/idm: use cluster secrets
This commit is contained in:
parent
deaa423c86
commit
7b95308f0d
8 changed files with 5 additions and 3 deletions
|
@ -5,10 +5,8 @@ let
|
||||||
in
|
in
|
||||||
|
|
||||||
{
|
{
|
||||||
age.secrets.idmServiceAccountCredentials.file = ./secrets/service-account-${config.networking.hostName}.age;
|
|
||||||
|
|
||||||
systemd.services.kanidm-unixd.serviceConfig = {
|
systemd.services.kanidm-unixd.serviceConfig = {
|
||||||
EnvironmentFile = config.age.secrets.idmServiceAccountCredentials.path;
|
EnvironmentFile = cluster.config.services.idm.secrets.serviceAccountCredentials.path;
|
||||||
};
|
};
|
||||||
|
|
||||||
services.kanidm = {
|
services.kanidm = {
|
||||||
|
|
|
@ -33,6 +33,10 @@
|
||||||
./policies/soda.nix
|
./policies/soda.nix
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
secrets.serviceAccountCredentials = {
|
||||||
|
nodes = config.services.idm.nodes.client;
|
||||||
|
shared = false;
|
||||||
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
dns.records = let
|
dns.records = let
|
||||||
|
|
Loading…
Reference in a new issue