| * might be easier to write a systemd unit (e.g. oneshot + optional timer or ExecStartPre) which does the credential pull ratherer than relying on boot user scripts.
Ideally the boot userscript just does a nixos-rebuild switch --flake {flake URL} and nothing else
|