!BgJZHVOYkwVcEKLAyM:nixos.org

NixOS Deployments

1139 Members
NixOS Deployment tooling274 Servers

Load older messages


SenderMessageTime
25 Jun 2025
@terje.furenes:matrix.orgterje.furenes joined the room.15:41:46
@gkaklas:matrix.orggkak.laₛ changed their display name from gkaklas to gkak.laₛ.17:50:21
26 Jun 2025
@kernz9:matrix.orgkernz9 joined the room.05:39:17
@blaxxmith:matrix.orgblaxxmith joined the room.09:09:40
@zekeriyaoz:matrix.orgmao zedong changed their profile picture.21:42:57
@zekeriyaoz:matrix.orgmao zedong changed their display name from nixosfanboy to liselifilozof.21:44:02
27 Jun 2025
@redstone-menace:matrix.orgR̴̨͕͇͍̞̮̐̅͆̌̀̉̐͋̈́̃̀͒́̎̅̚̚̚͠͝Ĕ̵̡̛͖͖̟̙̫̱͈̘̞̭͍͍͑̌̄͑̓̋̓̀̈̏̈́͊̇͊͆̉͂̏̀̃̚͘͝͝ͅͅD̶̡̢͔̱̖̮͙͉̘̺͓͍̩̮͈͍͗̃̀̏͌͘͜ͅŚ̸̬̭̯̬͙͇͓̬̩̳̤͚͓̤̩̺͉͖̉͛̓̿̎͊̿̆́̐͂̇͌̄̇̓͘ͅͅT̴̞̫̘̝͇͔̟̪̪̦͂̔̎̀̎ͅŎ̷̡̬̹̪͈̭̣͈̭̭͉̦̖̝̘̪͖͔̥̦̘̻̳Ṋ̶̛̫͈̳̘͚̜̔̋͆̅̈́͊̑͊̉̌̈́̾͑̈́̚ͅË̸̡̨̨̛͇̜̖͔͖̻̟̗̠̙͓̘̗̥͉͇̜͑͆͊͑͑̀̓͒͜͝͝ changed their display name from Redstone to R̴̨͕͇͍̞̮̐̅͆̌̀̉̐͋̈́̃̀͒́̎̅̚̚̚͠͝Ĕ̵̡̛͖͖̟̙̫̱͈̘̞̭͍͍͑̌̄͑̓̋̓̀̈̏̈́͊̇͊͆̉͂̏̀̃̚͘͝͝ͅͅD̶̡̢͔̱̖̮͙͉̘̺͓͍̩̮͈͍͗̃̀̏͌͘͜ͅŚ̸̬̭̯̬͙͇͓̬̩̳̤͚͓̤̩̺͉͖̉͛̓̿̎͊̿̆́̐͂̇͌̄̇̓͘ͅͅT̴̞̫̘̝͇͔̟̪̪̦͂̔̎̀̎ͅŎ̷̡̬̹̪͈̭̣͈̭̭͉̦̖̝̘̪͖͔̥̦̘̻̳Ṋ̶̛̫͈̳̘͚̜̔̋͆̅̈́͊̑͊̉̌̈́̾͑̈́̚ͅË̸̡̨̨̛͇̜̖͔͖̻̟̗̠̙͓̘̗̥͉͇̜͑͆͊͑͑̀̓͒͜͝͝.00:55:45
@psibi:matrix.org@psibi:matrix.org left the room.09:38:14
@dramosac:matrix.orgDaniel Ramos joined the room.18:33:15
@dramosac:matrix.orgDaniel Ramos

Hello folks 👋

I’m trying to deploy user passwords declaratively with sops-nix, but before moving to sops-nix, I’d like to at least manage user passwords declaratively in a basic way.

I started with something like:

users.users.cris = {
  isNormalUser = true;
  password = "changeme";
};

I can SSH into the machine and then su cris using the "changeme" password without issues.

Later, I change it to:

users.users.cris = {
  isNormalUser = true;
  password = "somethingelse";
};

I deploy using deploy-rs, but when I SSH into the machine and run su cris, the password remains the old "changeme", not the new "somethingelse".

Why does this happen? Is this expected behavior in NixOS? Where does this behavior come from?
Thanks in advance!

18:39:01
@emilazy:matrix.orgemilydo you have mutableUsers on?18:45:29
@emilazy:matrix.orgemilyby default the password options only set initial password, it's evil and you should turn it off18:45:47
@dramosac:matrix.orgDaniel RamosI think It might be that! I dont' have configured neither mutableUsers = true or false. Where is this config living? under <??>.mutableUsers? Sorry I'm a nix newbie 😅19:03:42
@dramosac:matrix.orgDaniel Ramos * I think It might be that! I dont' have configured neither mutableUsers = true or false, so I think it has to be retrieving the default config. Where is this config living? under <??>.mutableUsers? Sorry I'm a nix newbie 😅 19:04:04
@jappie:jappie.devjappie users.mutableUsers
you can look up such options on search.nixos.org: https://search.nixos.org/options?query=mutableUsers
19:07:06
@dramosac:matrix.orgDaniel Ramosthanks you so much!!19:11:11
@emilazy:matrix.orgemilyfwiw, I recommend using precomputed password hashes, even when using encryption19:34:27
@emilazy:matrix.orgemily so hashedPassword{,File} rather than password{,File} 19:34:45
@emilazy:matrix.orgemily (you can make them ahead of time with mkpasswd0 19:34:54
@emilazy:matrix.orgemily * (you can make them ahead of time with mkpasswd) 19:34:55
@zekeriyaoz:matrix.orgmao zedong changed their profile picture.20:27:42
@zekeriyaoz:matrix.orgmao zedong changed their display name from liselifilozof to mao zedong.20:28:02
@dramosac:matrix.orgDaniel Ramosok, thanks you!22:18:00
28 Jun 2025
@nyxvectar:matrix.orgNyxvectar changed their display name from Вектарис Янов to Rtsingo Су. Nyxvectar.02:51:55
@nyxvectar:matrix.orgNyxvectar changed their profile picture.06:32:27
@dramosac:matrix.orgDaniel RamosGood morning, folks. I have another question. I’m trying to set up nix-sops with deploy-rs, but I haven’t been able to get it working. Do you have any resources or GitHub repos where I can find a similar setup where can I learn from? Thank you so much.08:30:40
@jason-m:matrix.orgJason joined the room.16:19:57
@bizmyth:matrix.orgbizmyth joined the room.16:53:52
29 Jun 2025
@j:jfi.czjficz Can't help with sops much but I recommend to check out agenix if you're still exploring and are not fixed on sops. It is (imho) much more cleanly integrated with Nix. 21:40:54
@jonhermansen:matrix.orgjonhermansen joined the room.22:08:50

Show newer messages


Back to Room ListRoom Version: 6