{config, ...}: {
sops.secrets.rootPwd.neededForUsers = true;
sops.secrets.liljamoPwd.neededForUsers = true;
roles.base = {
root.hashedPasswordFile = config.sops.secrets.rootPwd.path;
primaryUser = {
username = "liljamo";
hashedPasswordFile = config.sops.secrets.liljamoPwd.path;
};
};
roles.tailscale = {
enable = true;
enableSSH = true;
};
}