Skip to content

Feat/sops: add syncthing with sops-managed GUI password - #2

Merged
hxsnaatdev merged 5 commits into
mainfrom
feat/sops
Jul 10, 2026
Merged

Feat/sops: add syncthing with sops-managed GUI password#2
hxsnaatdev merged 5 commits into
mainfrom
feat/sops

Conversation

@hxsnaatdev

Copy link
Copy Markdown
Owner
  • enable sops-nix for nix-darwin
  • add age recipient config and encrypted secrets file
  • declare Syncthing GUI password secret
  • configure Home Manager Syncthing service
  • add SecondBrain folder and m1 peer

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR introduces SOPS-managed secrets for a Syncthing GUI password and adds a Home Manager Syncthing configuration for the nix-darwin host M4.

Changes:

  • Add SOPS configuration (.sops.yaml) and an encrypted secrets file (secrets.yaml) containing syncthing.guiPassword.
  • Add nix-darwin sops configuration for host M4, including a declared Syncthing GUI password secret.
  • Add and import a Home Manager services.syncthing configuration intended to consume the secret.

Reviewed changes

Copilot reviewed 5 out of 5 changed files in this pull request and generated 2 comments.

Show a summary per file
File Description
secrets.yaml Adds encrypted Syncthing GUI password and SOPS metadata.
hosts/M4/darwin.nix Declares SOPS defaults and a syncthing/guiPassword secret for the host.
home/syncthing.nix Adds Home Manager Syncthing service configuration including GUI credentials and folder/device settings.
home/home-manager.nix Imports the new Syncthing Home Manager module.
.sops.yaml Configures SOPS creation rules using an age recipient for secrets.yaml.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread hosts/M4/darwin.nix
Comment on lines +19 to +23
sops = {
defaultSopsFile = ../../secrets.yaml;
defaultSopsFormat = "yaml";

age.keyFile = "/Users/ariz/.config/sops/age/keys.txt";
Comment thread home/syncthing.nix
Comment on lines +1 to +9
{syncthingGuiPasswordFile, ...}: {
services.syncthing = {
enable = true;

guiAddress = "127.0.0.1:8384";
guiCredentials = {
username = "ariz";
passwordFile = syncthingGuiPasswordFile;
};
@hxsnaatdev
hxsnaatdev merged commit df7db94 into main Jul 10, 2026
1 of 3 checks passed
@hxsnaatdev
hxsnaatdev deleted the feat/sops branch July 11, 2026 10:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants