diff --git a/flake.lock b/flake.lock index 0a7f5a79..14b12567 100644 --- a/flake.lock +++ b/flake.lock @@ -746,11 +746,11 @@ ] }, "locked": { - "lastModified": 1739973884, - "narHash": "sha256-XXeb1CpfCWdCJJld/KkpuvNWMfdH96O+pIQ1olgVAGg=", + "lastModified": 1741194353, + "narHash": "sha256-FkDRsNpV9eEDBL95X/NlUhFOSkGSybGQt2MekbH/bqk=", "ref": "main", - "rev": "09a5f2c01a6a88634d4524e7868d6b01a9b59235", - "revCount": 182, + "rev": "c977ccd8a4f1ef98fdfa754e9b86a0659cc6ba10", + "revCount": 184, "type": "git", "url": "ssh://xin-secrets-ro/qbit/xin-secrets.git" }, diff --git a/hosts/h/default.nix b/hosts/h/default.nix index 7359c907..070ed135 100644 --- a/hosts/h/default.nix +++ b/hosts/h/default.nix @@ -153,6 +153,11 @@ in owner = "root"; sopsFile = config.xin-secrets.h.secrets.services; }; + qbit_at_segfault_pass_file = { + mode = "400"; + owner = "root"; + sopsFile = config.xin-secrets.h.secrets.services; + }; mcchunkie_at_suah_pass_file = { mode = "400"; owner = "root"; @@ -360,13 +365,17 @@ in mailserver = { enable = true; fqdn = "mail.suah.dev"; - domains = [ "suah.dev" ]; + domains = [ "suah.dev" "segfault.rodeo" ]; certificateScheme = "acme-nginx"; localDnsResolver = false; loginAccounts = { + "qbit@segfault.rodeo" = { + aliases = [ "postmaster@segfault.rodeo" "aaron@segfault.rodeo" ]; + hashedPasswordFile = "${config.sops.secrets.qbit_at_segfault_pass_file.path}"; + }; "qbit@suah.dev" = { hashedPasswordFile = "${config.sops.secrets.qbit_at_suah_pass_file.path}"; aliases = [ "postmaster@suah.dev" "aaron@suah.dev" ];