diff --git a/services/kanidm/default.nix b/services/kanidm/default.nix index c245079..c7baaa1 100644 --- a/services/kanidm/default.nix +++ b/services/kanidm/default.nix @@ -17,7 +17,8 @@ }; }; - # Provisioning - initial users/groups + # Provision base groups only - users are managed via CLI + # See docs/user-management.md for details provision = { enable = true; idmAdminPasswordFile = config.vault.secrets.kanidm-idm-admin.outputDir; @@ -28,10 +29,7 @@ ssh-users = { }; }; - persons.torjus = { - displayName = "Torjus"; - groups = [ "admins" "users" "ssh-users" ]; - }; + # Regular users (persons) are managed imperatively via kanidm CLI }; }; @@ -46,7 +44,7 @@ extraDomainNames = [ "${config.networking.hostName}.home.2rjus.net" ]; }; - # Vault secret for idm_admin password + # Vault secret for idm_admin password (used for provisioning) vault.secrets.kanidm-idm-admin = { secretPath = "kanidm/idm-admin-password"; extractKey = "password";