!BgJZHVOYkwVcEKLAyM:nixos.org

NixOS Deployments

1247 Members
NixOS Deployment tooling308 Servers

Load older messages


SenderMessageTime
28 Apr 2025
@louis2747:matrix.orgLouis2747 joined the room.14:53:33
@jrpo:mozilla.orgjrpo joined the room.21:53:31
29 Apr 2025
@federicodschonborn:matrix.org@federicodschonborn:matrix.org changed their display name from This LEGO® Worm™ is licensed under the terms of the he/him or they/them pronouns, at your choice to This legally distinct plastic brick is licensed under the terms of the he/him or they/them pronouns, at your choice.14:39:49
@regalk:regalk.devregalk joined the room.22:29:43
@ygt:matrix.org@ygt:matrix.org left the room.23:39:40
30 Apr 2025
@devalot:matrix.orgPeter Jones left the room.09:06:37
@sheeldotme:matrix.org@sheeldotme:matrix.org left the room.14:23:10
1 May 2025
@rosariopulella:matrix.orgrosariopulella changed their display name from Rosario Pulella to Rosuavio.20:08:12
@solhvemjsun:matrix.orgSol joined the room.21:21:33
@oak:universumi.fioak 🏳️‍🌈♥️ changed their display name from oak - mikatammi.fi to oak.23:17:49
@oak:universumi.fioak 🏳️‍🌈♥️ changed their display name from oak to oak 🫱⭕🫲.23:18:20
2 May 2025
@penguin_brian:matrix.orgBrian May joined the room.01:19:41
@gonzo7d0:gonzo.cloudGZ7d0 changed their display name from GonZo7d0 to GZ7d0.15:18:40
3 May 2025
@dumpy:fedora.im@dumpy:fedora.im joined the room.23:01:44
@mjolnir:nixos.orgmjolnir banned @dumpy:fedora.im@dumpy:fedora.im (spam).23:01:45
5 May 2025
@mscre:xmr.se@mscre:xmr.se joined the room.04:17:23
@edsoncsouza:matrix.org@edsoncsouza:matrix.org left the room.09:40:05
@kurnevsky:matrix.org@kurnevsky:matrix.org joined the room.11:06:08
@kurnevsky:matrix.org@kurnevsky:matrix.org Hi. Is there a way to compress data from substituters? When I specify nixos-rebuild switch --option extra-substituters ssh://... which points to my other nix pc, it starts to download everything from it, and the download size is much bigger than without extra-substituters. I have ssh compression enabled, but it seems it doesn't make it much better :) 11:09:58
@googleson78:tryp.io@googleson78:tryp.io left the room.15:00:18
@federicodschonborn:matrix.org@federicodschonborn:matrix.org changed their display name from This legally distinct plastic brick is licensed under the terms of the he/him or they/them pronouns, at your choice to This LEGO© Worm™ is licensed under the terms of the he/him or they/them pronouns, at your choice.20:48:42
@mscre:xmr.se@mscre:xmr.se left the room.22:12:44
@ortolanbunting3002:tchncs.deortolanbunting3002

Is there a secret provisioning solution, that only does the provisioning part? I'd like to keep my secrets in git-crypt at rest.

23:59:35
6 May 2025
@flare:matrix.darkc0de.oneflareum, I use sops-nix but that also handles the encryption00:19:02
@2007corolla:matrix.org2007 Corolla joined the room.02:45:11
@magic_rb:matrix.redalder.orgmagic_rbI think its similar ish to git crypt though07:07:21
@federicodschonborn:matrix.org@federicodschonborn:matrix.org changed their display name from This LEGO© Worm™ is licensed under the terms of the he/him or they/them pronouns, at your choice to This LEGO® Worm™ is licensed under the terms of the he/him or they/them pronouns, at your choice.09:13:05
@flare:matrix.darkc0de.oneflareyes but there is a dedicated nix module that lets you use age encryption derived from ssh keys and lets you encrypt to multiple recipients12:29:54
@flare:matrix.darkc0de.oneflareI migrate my secrets encrypted with the host I am configuring with ssh and the point the host config at those encrypted files and the host ssh key and it provisions and sets the uid and gid of the unencrypted secrets under the /run/secrets dir with mode 0400 i believe12:31:25
@flare:matrix.darkc0de.oneflareIts not just limited to gpg, however I have never used git-crypt12:32:37

Show newer messages


Back to Room ListRoom Version: 6