Would you mind if I extracted SOPS support from https://github.com/nix-community/robotnix/pull/203 and made PR for that? And if you don't want the whole thing downstream, then at least minimal changes to support that downstream? I already used that for my Pixel and it would be nice if I didn't have to drop it.