{ ristrettoSigningKeyPath , stripeSecretKeyPath , monitoringvpnKeyDir , monitoringvpnEndpoint , monitoringvpnIPv4 , sshUsers , letsEncryptAdminEmail , issuerDomains , allowedChargeOrigins , ... }: { deployment.secrets = { "ristretto-signing-key".source = ristrettoSigningKeyPath; "stripe-secret-key".source = stripeSecretKeyPath; "monitoringvpn-secret-key".source = "${monitoringvpnKeyDir}/${monitoringvpnIPv4}.key"; "monitoringvpn-preshared-key".source = "${monitoringvpnKeyDir}/preshared.key"; }; services.private-storage.sshUsers = sshUsers; services.private-storage.monitoring.vpn.client = { enable = true; ip = monitoringvpnIPv4; endpoint = monitoringvpnEndpoint; endpointPublicKeyFile = "${monitoringvpnKeyDir}/server.pub"; }; services.private-storage-issuer = { letsEncryptAdminEmail = letsEncryptAdminEmail; domains = issuerDomains; allowedChargeOrigins = allowedChargeOrigins; }; system.stateVersion = "19.03"; }