!XLCFfvFhUkYwOMLbVx:nixos.org

agenix

332 Members
age-encrypted secrets for NixOS https://github.com/ryantm/agenix/99 Servers

Load older messages


SenderMessageTime
1 Jul 2025
@zororg:matrix.orgzororgNote, I mean to say this only for my personal desktop nixos usage. I'm no devops engineer or work with remote/kube/dockers for CI/cd or deployment works14:57:35
@k900:0upti.meK900GPG is terrible15:19:09
@k900:0upti.meK900Don't use GPG15:19:10
@zororg:matrix.orgzororgAh, Cool. I don't want to waste your time much. But may I know how? I mean, how can I replace them by using age+sops or agenix? cause I was trying to read as much as I could. I barely found 2-3 articles and some discussions15:21:00
@k900:0upti.meK900What problem are you trying to solve15:21:10
@k900:0upti.meK900And why15:21:12
@zororg:matrix.orgzororgActually no problem as of now. I was trying to setup new nixos system, and thought to setup ssh and gpg. And then stumbled on declarative way of doing secrets via sops-nix or agenix. Since then Idk what best setup I can do15:22:10
@zororg:matrix.orgzororgMy main usecase are: Normal desktop, git ssh pushes, managing passwords15:22:44
@k900:0upti.meK900Just get a yubikey and a password manager15:22:56
@zororg:matrix.orgzororgyubikey is out of option for me.15:23:55
@k900:0upti.meK900Why?15:24:07
@zororg:matrix.orgzororgI use keepassxc. Although my questions would, can sops+age replace gpg and keepass for me?15:24:27
@zororg:matrix.orgzororg expensive, and I dont real usage with it for now. 15:24:40
@k900:0upti.meK900No15:24:53
@zororg:matrix.orgzororg* expensive, and I dont real usage with it for now. Maybe when I have too many setups and machines (one day...)15:24:54
@k900:0upti.meK900sops/age are the wrong tool for this15:24:59
@k900:0upti.meK900Entirely15:25:00
@k900:0upti.meK900And keepassxc has an SSH agent15:25:08
@k900:0upti.meK900So just keep using that15:25:10
@zororg:matrix.orgzororgThen only use of them are in deployment?15:25:17
@k900:0upti.meK900Yes15:25:25
@zororg:matrix.orgzororgah, thats the conclusion I came to as well. Simply use gnupg and keepass, right?15:26:11
@k900:0upti.meK900No gnupg15:26:25
@k900:0upti.meK900Just use keepass15:26:27
@zororg:matrix.orgzororgthen file encryption, git signing?15:26:50
@k900:0upti.meK900SSH signatures for git if you really want to15:27:25
@k900:0upti.meK900Though it's fine to just not15:27:28
@k900:0upti.meK900age for encrypting files if you really need something public key based15:27:41
@k900:0upti.meK900But honestly that's not a thing you generally want15:27:52
@zororg:matrix.orgzororgsounds sensible.15:28:11

Show newer messages


Back to Room ListRoom Version: 6