Sender | Message | Time |
---|---|---|
27 May 2025 | ||
https://matrix.to/#/!XLCFfvFhUkYwOMLbVx:nixos.org/$g_OpCDha4vege-oXbuwHfZE-iDRvLC-abhfdkuZTq3I?via=nixos.org&via=matrix.org&via=frodux.net | 10:41:37 | |
* Looks like I stumbled upon an anti-pattern: https://matrix.to/#/!XLCFfvFhUkYwOMLbVx:nixos.org/$g_OpCDha4vege-oXbuwHfZE-iDRvLC-abhfdkuZTq3I?via=nixos.org&via=matrix.org&via=frodux.net | 10:42:10 | |
Not sure exactly how to do things properly though :( | 10:42:31 | |
ChatGPT is recommending an alternative approach:
It works, though I suspect it compromises reproducibility... Signing off for the evening. If there's a better way, I'd be keen to learn! | 11:03:22 | |
11:15:30 | ||
28 May 2025 | ||
Claude eventually helped me find a more pleasant solution based on The initial goal was to create a self-contained, minimal flake.nix that integrated nix-darwin, home-manager, and agenix. The desired end state is a macOS system with an agenix-encrypted secret decrypted and stored at ~/secret1.txt (by home-manager). The following
The secrets are defined in
If any Nix experts observe any flaws in this approach, please raise them now. Otherwise, I hope it helps:
| 03:49:26 | |
15:17:31 | ||
31 May 2025 | ||
20:52:37 | ||
27 Oct 2022 | ||
14:03:00 | ||
15:00:21 | ||
29 Oct 2022 | ||
07:01:32 | ||
31 Oct 2022 | ||
20:39:49 | ||
6 Nov 2022 | ||
11:13:57 | ||
12 Nov 2022 | ||
15:03:58 | ||
is it alright to check secret files into a public git repo? | 15:04:41 | |
Ash: how much do you trust age encryption? | 15:18:48 | |
i guess a better way to phrase the question is "is it reasonable to trust age enough to do that" | 15:35:49 | |
Most people trust it enough | 15:40:04 | |
Anyone answering that for you who isn't you is probably doing some form of appeal-to-authority, y'know? Its author is great, but everyone is fallible, so you gotta figure out your risk tolerance based on what info you want to protect. Typical "likeliness of compromise vs severity if compromised" kind of considerations. | 18:23:32 | |
13 Nov 2022 | ||
20:05:32 | ||
16 Nov 2022 | ||
20:34:23 | ||
17 Nov 2022 | ||
13:27:40 | ||
19 Nov 2022 | ||
10:40:04 | ||
21 Nov 2022 | ||
18:56:05 | ||
18:56:23 | ||
25 Nov 2022 | ||
03:09:53 | ||
26 Nov 2022 | ||
19:19:50 | ||
29 Nov 2022 | ||
17:51:47 | ||
3 Dec 2022 | ||
15:50:06 | ||
5 Dec 2022 | ||
Is anyone using agenix with deploy-rs? deploy-rs fails telling me that `/nix/store/xxxx-source/secrets` does not exist | 02:22:39 |