From 8e08dd69705d07c3e4782856b49e3732f273703f Mon Sep 17 00:00:00 2001 From: Aspen Smith Date: Thu, 18 Jan 2024 10:32:03 -0500 Subject: feat(grfn/system): Add windtunnel bot github token secret Change-Id: Ib67526e782fe0bedecd24d9c48dcf189fb8b5b02 Reviewed-on: https://cl.tvl.fyi/c/depot/+/10664 Reviewed-by: aspen Autosubmit: aspen Tested-by: BuildkiteCI --- users/grfn/system/system/machines/mugwump.nix | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) (limited to 'users/grfn/system/system/machines/mugwump.nix') diff --git a/users/grfn/system/system/machines/mugwump.nix b/users/grfn/system/system/machines/mugwump.nix index 5b3cf1204904..3d4de5df1d87 100644 --- a/users/grfn/system/system/machines/mugwump.nix +++ b/users/grfn/system/system/machines/mugwump.nix @@ -96,6 +96,12 @@ with lib; group = "keys"; mode = "0440"; }; + + windtunnel-bot-github-token = { + file = secret "windtunnel-bot-github-token"; + group = "keys"; + mode = "0440"; + }; }; services.fail2ban = { @@ -295,6 +301,6 @@ with lib; users.users."buildkite-agent-mugwump-1" = { isSystemUser = true; - extraGroups = [ "docker" ]; + extraGroups = [ "docker" "keys" ]; }; } -- cgit 1.4.1