diff options
Diffstat (limited to 'ops/secrets/mkSecrets.nix')
-rw-r--r-- | ops/secrets/mkSecrets.nix | 19 |
1 files changed, 19 insertions, 0 deletions
diff --git a/ops/secrets/mkSecrets.nix b/ops/secrets/mkSecrets.nix new file mode 100644 index 000000000000..7a39a418a884 --- /dev/null +++ b/ops/secrets/mkSecrets.nix @@ -0,0 +1,19 @@ +# Expose secrets as part of the tree, making it possible to validate +# their paths at eval time. +# +# Note that encrypted secrets end up in the Nix store, but this is +# fine since they're publicly available anyways. +{ depot, pkgs, ... }: +path: secrets: + +let + inherit (builtins) attrNames listToAttrs; + + # Import a secret to the Nix store + declareSecret = name: pkgs.runCommandNoCC name {} '' + cp ${path + "/${name}"} $out + ''; +in depot.nix.readTree.drvTargets (listToAttrs ( + map (name: { inherit name; value = declareSecret name; }) + (attrNames secrets) +)) |