This template is the result of running the nix-darwin "from scratch" instructions found at https://github.com/nix-darwin/nix-darwin?tab=readme-ov-file#step-1-creating-flakenix plus some small changes for Determinate. Enhanced with Touch ID sudo and modular AI-friendly structure.
This template includes sops-nix by default with minimal base wiring:
- flake.nix:
sops-nixinput and darwin module are enabled - modules/darwin/sops.nix: minimal base
sopsconfiguration - modules/darwin/sops-secrets.nix: secret declarations and runtime bindings
- .sops.yaml: creation rules for
secrets/*.yaml
To start using secrets:
- Replace
AGE_PUBLIC_KEY_PLACEHOLDERin .sops.yaml with your age public key. - Add your secret entries in modules/darwin/sops-secrets.nix.
- Create/edit encrypted secrets with
sops secrets/<name>.yaml.