!PbtOpdWBSRFbEZRLIf:numtide.com

Nix Community Projects

661 Members
Meta discussions related to https://nix-community.org. (For project specific discussions use github issues or projects own matrix channel). Need help from an admin? Open an issue on https://github.com/nix-community/infra/issues166 Servers

Load older messages


SenderMessageTime
24 Aug 2021
@tejasagarwal:matrix.orgTejas Agarwal left the room.17:06:30
26 Aug 2021
@nix-community-bot:nixos.devnix-community-bot [nix-community/infra] ryantm pushed to master: update nixpkgs-update * when using updateScript, ensure update doesn't already exist - https://github.com/nix-community/infra/commit/3195b9c00b6a1b3b3ff76605b80240d6f5abc007 01:41:31
@ryantm:matrix.orgryantmdeploying to build0201:42:52
@sandro:supersandro.deSandro Are you done yet ryantm ? 09:32:59
@mic92:nixos.devMic92I guess so09:36:12
@ryantm:matrix.orgryantmOh yes sorry.13:33:46
@zimbatm:numtide.comJonas Chevalier Mic92: why don't we switch to using sops-nix for the infra? 14:21:15
@mic92:nixos.devMic92@zimbatm: I guess nothing speaks against it.14:21:42
@zimbatm:numtide.comJonas Chevaliermight as well exercise it14:21:57
@mic92:nixos.devMic92Does terraform need any secrets?14:22:37
@zimbatm:numtide.comJonas Chevaliereven if that's the case, terraform-sops is also a thing14:23:12
@mic92:nixos.devMic92Right. I was pretty sure there was something14:23:24
@mic92:nixos.devMic92Than it's uniform14:23:35
@mic92:nixos.devMic92In october I plan to add support for age but the current ssh rsa key support will stay as well. Right now we have our gpg keys anyway so this is probably the easiest option to switch to.14:25:04
@zimbatm:numtide.comJonas Chevalieragreed.14:36:00
@zimbatm:numtide.comJonas Chevaliermaybe one day we can get rid of GPG, that would be nice14:36:14
@mic92:nixos.devMic92Yeah. I definitly will add this because I want to migrate some servers in university to it as well.14:58:05
@mic92:nixos.devMic92It also makes sops-nix nicer because you no longer need the ssh private host server key for bootstrapping.14:58:33
@mic92:nixos.devMic92Age only needs public keys whereas gpg needs public keys signed by the private key.14:59:11
@zimbatm:numtide.comJonas Chevalierdo you thing sops is still worth it if we use age, or should we just use age without the indirection?15:16:00
@mic92:nixos.devMic92Personally I like the sops editor over having one file per secret15:20:52
@zimbatm:numtide.comJonas Chevalierok, you convinced me :D15:23:39
@timdeh:matrix.orgnrdxpif you have a yubikey, you might like this pr to agenix 😉 https://github.com/ryantm/agenix/pull/4616:34:44
@ryantm:matrix.orgryantmI'm not really arguing against sops-nix, but there's arguments for having one file per secret too, like it is simpler to understand, copy secrets between places, and potentially easier to recover from some issue.16:37:40
@ryantm:matrix.orgryantmAlso better interoperability, theoretically.16:38:13
@zimbatm:numtide.comJonas Chevalier nice. ryantm can I send you a yubikey? 16:41:58
@zimbatm:numtide.comJonas Chevalieranother argument is that incremental rebuild is better16:42:46
@ryantm:matrix.orgryantm Jonas Chevalier: Sure, I won't object 😀 I have some really old one that doesn't do the new fancy stuff. 16:42:50
@zimbatm:numtide.comJonas ChevalierDM me your address and you'll get one :D16:43:15
@andi:kack.it@andi:kack.itIs there a Yubikey that does USB-A + USB-C yet?16:46:26

Show newer messages


Back to Room ListRoom Version: 6