{...}: { sops = { # TODO: hardcoding defaultSopsFile = ../../../secrets/silver.yaml; age.sshKeyPaths = ["/persist/etc/ssh/ssh_host_ed25519_key"]; secrets."root-pw" = {neededForUsers = true;}; secrets."user-pw" = {neededForUsers = true;}; }; }