{ config, inputs, ... }: { nix.settings = { trusted-substituters = [ "http://jeeves:5000" ]; substituters = [ "http://jeeves:5000/?priority=1&want-mass-query=true" ]; trusted-public-keys = [ "cache.tmmworkshop.com:jHffkpgbmEdstQPoihJPYW9TQe6jnQbWR2LqkNGV3iA=" ]; }; services.tailscale = { enable = true; openFirewall = true; authKeyFile = config.sops.secrets.tailscale_auth_key.path; # OAuth client secrets create ephemeral nodes by default. NixOS machines # are persistent and should enroll without interactive device approval. authKeyParameters = { ephemeral = false; preauthorized = true; }; extraUpFlags = [ "--advertise-tags=tag:nixos" ]; }; sops = { age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; secrets.tailscale_auth_key = { sopsFile = "${inputs.self}/users/secrets.yaml"; owner = "root"; mode = "0400"; }; }; }