diff --git a/config/basic/impermanence.nix b/config/basic/impermanence.nix index b69d367..a6fac1e 100644 --- a/config/basic/impermanence.nix +++ b/config/basic/impermanence.nix @@ -31,6 +31,10 @@ in { "/var/log" "/var/lib/systemd" "/var/lib/nixos" + { + directory = "/var/tmp/nix-import-encrypted/"; + mode = "0777"; + } { directory = "/var/tmp/agenix-rekey"; mode = "0777"; diff --git a/nix/rage-decrypt-and-cache.sh b/nix/rage-decrypt-and-cache.sh index 8ee9f52..3291530 100755 --- a/nix/rage-decrypt-and-cache.sh +++ b/nix/rage-decrypt-and-cache.sh @@ -23,7 +23,7 @@ new_name="$(sha512sum "$file")" new_name="${new_name:0:32}-${basename//"/"/"%"}" # Derive the path where the decrypted file will be stored -out="/tmp/nix-import-encrypted/$new_name" +out="/var/tmp/nix-import-encrypted/$new_name" mkdir -p "$(dirname "$out")" # Decrypt only if necessary