diff --git a/modules/age.nix b/modules/age.nix index 86c4447..6d97941 100644 --- a/modules/age.nix +++ b/modules/age.nix @@ -14,6 +14,11 @@ with lib; let users = config.users.users; + sysusersEnabled = + if isDarwin + then false + else options.systemd ? sysusers && config.systemd.sysusers.enable; + mountCommand = if isDarwin then '' @@ -261,44 +266,66 @@ in { } ]; } - (optionalAttrs (!isDarwin) { + # When using sysusers we no longer be started as an activation script + # because those are started in initrd while sysusers is started later. + systemd.services.agenix-install-secrets = mkIf sysusersEnabled { + wantedBy = ["sysinit.target"]; + after = ["systemd-sysusers.service"]; + unitConfig.DefaultDependencies = "no"; + + serviceConfig = { + Type = "oneshot"; + ExecStart = pkgs.writeShellScript "agenix-install" ( + builtins.concatStringsSep "\n" [ + newGeneration + installSecrets + chownSecrets + ] + ); + RemainAfterExit = true; + }; + }; + # Create a new directory full of secrets for symlinking (this helps # ensure removed secrets are actually removed, or at least become # invalid symlinks). - system.activationScripts.agenixNewGeneration = { - text = newGeneration; - deps = [ - "specialfs" - ]; - }; + system = mkIf (!isDarwin && !sysusersEnabled) { + activationScripts.agenixNewGeneration = { + text = newGeneration; + deps = [ + "specialfs" + ]; + }; - system.activationScripts.agenixInstall = { - text = installSecrets; - deps = [ - "agenixNewGeneration" - "specialfs" - ]; - }; + activationScripts.agenixInstall = { + text = installSecrets; + deps = [ + "agenixNewGeneration" + "specialfs" + ]; + }; - # So user passwords can be encrypted. - system.activationScripts.users.deps = ["agenixInstall"]; + # So user passwords can be encrypted. + activationScripts.users.deps = ["agenixInstall"]; - # Change ownership and group after users and groups are made. - system.activationScripts.agenixChown = { - text = chownSecrets; - deps = [ - "users" - "groups" - ]; - }; + # Change ownership and group after users and groups are made. + activationScripts.agenixChown = { + text = chownSecrets; + deps = [ + "users" + "groups" + ]; + }; - # So other activation scripts can depend on agenix being done. - system.activationScripts.agenix = { - text = ""; - deps = ["agenixChown"]; + # So other activation scripts can depend on agenix being done. + activationScripts.agenix = { + text = ""; + deps = ["agenixChown"]; + }; }; }) + (optionalAttrs isDarwin { launchd.daemons.activate-agenix = { script = ''