!XLCFfvFhUkYwOMLbVx:nixos.org

agenix

328 Members
age-encrypted secrets for NixOS https://github.com/ryantm/agenix/96 Servers

Load older messages


SenderMessageTime
17 Nov 2022
@ctx:kungfu-g.ripREASON...UNKNOWN changed their display name from ctx to REASON...UNKNOWN.13:27:40
19 Nov 2022
@tomchab:matrix.orgtchab changed their display name from tomchab to tchab.10:40:04
21 Nov 2022
@sasha:serpantinka.xyzPlayer205 changed their display name from Александра Краснозерницкая to Player205.18:56:05
@sasha:serpantinka.xyzPlayer205 set a profile picture.18:56:23
25 Nov 2022
@darthpjb:matrix.orgJohn Bargman joined the room.03:09:53
26 Nov 2022
@ahsmha:matrix.orgahmed changed their display name from rh to ahmed.19:19:50
29 Nov 2022
@pl1y:matrix.orgpl1y joined the room.17:51:47
3 Dec 2022
@happyalu:matrix.orgAlok Parlikar changed their display name from happyalu to Alok Parlikar.15:50:06
5 Dec 2022
@ctx:kungfu-g.ripREASON...UNKNOWNIs anyone using agenix with deploy-rs? deploy-rs fails telling me that `/nix/store/xxxx-source/secrets` does not exist02:22:39
@ryantm:matrix.orgryantm REASON...UNKNOWN: can you share your relevant NixOS config? 02:30:03
@ctx:kungfu-g.ripREASON...UNKNOWN
In reply to @ryantm:matrix.org
REASON...UNKNOWN: can you share your relevant NixOS config?
This is my flake.nix https://0x0.st/ok0G.nix
02:31:48
@ctx:kungfu-g.ripREASON...UNKNOWNI can share one of the hosts too02:32:02
@ryantm:matrix.orgryantmIt would help to see all the lines for agenix at least.02:33:00
@ctx:kungfu-g.ripREASON...UNKNOWNaaa/host.nix https://0x0.st/ok0n.nix02:33:51
@ctx:kungfu-g.ripREASON...UNKNOWNAnd configuration in a sec02:34:02
@ctx:kungfu-g.ripREASON...UNKNOWNhttps://0x0.st/ok07.nix02:36:23
@ctx:kungfu-g.ripREASON...UNKNOWNThat's all the agenix stuff, except for secrets/secrets.nix02:38:00
@ryantm:matrix.orgryantmLooks pretty good. 02:38:09
@ryantm:matrix.orgryantmI don't typically use path + string for the file config so it would be a debugging step to write the real path out there.02:38:51
@ryantm:matrix.orgryantmAlso double check you've staged the secrets into your flake repo.02:39:38
@ctx:kungfu-g.ripREASON...UNKNOWN
In reply to @ryantm:matrix.org
Also double check you've staged the secrets into your flake repo.
Ah that is likely it. I have only an inkling that the repo contents affect things
02:40:44
@ctx:kungfu-g.ripREASON...UNKNOWNsecrets dir explicitly left out of repo in .gitignore02:40:59
@ctx:kungfu-g.ripREASON...UNKNOWNYeah. Seems to be working now.02:43:06
@ctx:kungfu-g.ripREASON...UNKNOWNSo I really ha e no choice but to commit secrets to my repo?02:43:35
@ctx:kungfu-g.ripREASON...UNKNOWN* So I really have no choice but to commit secrets to my repo?02:43:42
6 Dec 2022
@omlet:matrix.orgomlet left the room.03:18:07
7 Dec 2022
@drall.kj:matrix.orgdrall.kj joined the room.04:30:50
9 Dec 2022
@kukker:matrix.orgkukker joined the room.05:22:21
@pl1y:matrix.orgpl1yregarding the template discussion: current agenix decrypts the secret and writes it to disk. if someone needs post processing (transforming the secret, combining it with other config) one can use the `system.activationScripts` to read said secret and write it to another file, but needs to make sure it has the correct permissions and it's not committed to the nix store by accident.12:46:47
@pl1y:matrix.orgpl1ythere is currently a pull request, that would introduce templates, so one could specify a template with `@secret1@` template variables, and those would be replaced by the secrets, and handle the permissions.12:48:56

Show newer messages


Back to Room ListRoom Version: 6