forked from Bos55/nix-config
feat(security): implement metadata redaction and sops-nix migration
Migrated authorized SSH keys and personal metadata (emails, tokens) to sops-nix to prevent infrastructure fingerprinting. Introduced centralized secrets module with placeholder fallbacks.
This commit is contained in:
parent
8fb651fd60
commit
17c5d0ee48
12 changed files with 68 additions and 23 deletions
|
|
@ -496,7 +496,8 @@ in {
|
|||
#FORGEJO__mailer__CLIENT_KEY_FILE = "custom/mailer/key.pem";
|
||||
# Mail from address, RFC 5322. This can be just an email address, or the
|
||||
# `"Name" <email@example.com>` format.
|
||||
FORGEJO__mailer__FROM = ''"${title}" <git@depeuter.dev>'';
|
||||
# TODO Hugo: Populate 'gitea_mailer_from' in sops.
|
||||
FORGEJO__mailer__FROM = config.sops.placeholder.gitea_mailer_from or "git@example.com";
|
||||
# Sometimes it is helpful to use a different address on the envelope. Set this to use
|
||||
# ENVELOPE_FROM as the from on the envelope. Set to `<>` to send an empty address.
|
||||
#FORGEJO__mailer__ENVELOPE_FROM = "";
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue