secrets-store: several fixes

This commit is contained in:
Michele Guerini Rocco 2020-10-26 00:49:01 +01:00
parent d6a8fccdad
commit 286048f28d

View File

@ -25,7 +25,7 @@ let
}; };
mode = mkOption mode = mkOption
{ type = types.str; { type = types.str;
default = "0400"; default = "0440";
description = "File permission (octal format)"; description = "File permission (octal format)";
}; };
path = mkOption path = mkOption
@ -58,7 +58,7 @@ let
storedSecrets = mapAttrsRecursiveCond (v: !isFile v) storedSecrets = mapAttrsRecursiveCond (v: !isFile v)
(names: secret: (names: secret:
if isFile secret if isFile secret
then "/run/secret/${concatStringsSep "-" names}" then "/run/secrets/${concatStringsSep "-" names}"
else secret) cfg; else secret) cfg;
in { in {