secrets-store: several fixes

This commit is contained in:
Michele Guerini Rocco 2020-10-26 00:49:01 +01:00
parent b34a44098f
commit c57d1ffb63
Signed by: rnhmjoj
GPG Key ID: BFBAF4C975F76450

View File

@ -25,7 +25,7 @@ let
};
mode = mkOption
{ type = types.str;
default = "0400";
default = "0440";
description = "File permission (octal format)";
};
path = mkOption
@ -58,7 +58,7 @@ let
storedSecrets = mapAttrsRecursiveCond (v: !isFile v)
(names: secret:
if isFile secret
then "/run/secret/${concatStringsSep "-" names}"
then "/run/secrets/${concatStringsSep "-" names}"
else secret) cfg;
in {