diff --git a/nixos/modules/services/security/pocket-id.nix b/nixos/modules/services/security/pocket-id.nix index 9396185c2469..547b3df6db54 100644 --- a/nixos/modules/services/security/pocket-id.nix +++ b/nixos/modules/services/security/pocket-id.nix @@ -70,10 +70,13 @@ in ENCRYPTION_KEY = "/run/secrets/pocket-id/encryption-key"; }; description = '' - Environment variables which are loaded from the contents of the specified file paths. + Credentials which are loaded from the contents of the specified file paths. + This can be used to securely store tokens and secrets outside of the world-readable Nix store. - See [PocketID environment variables](https://pocket-id.org/docs/configuration/environment-variables). + See [PocketID environment variables](https://pocket-id.org/docs/configuration/environment-variables) (all with the `_FILE` suffix). + + Accepts an attrset mapping from the variable name *without its `_FILE` suffix* to the path on disk. Alternatively you can use `services.pocket-id.environmentFile` to define all the variables in a single file. '';