{ inputs, lib, config, ... }: { imports = [ inputs.sops-nix.nixosModules.sops ]; sops = { defaultSopsFile = ./secrets.yaml; age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; secrets.discogs_json = { mode = "0440"; owner = config.users.users.sstent.name; group = config.users.users.sstent.group; }; }; }