9 Mar 2025 |
| kiwicutter joined the room. | 23:34:49 |
10 Mar 2025 |
kiwicutter | So, ive been using agenix for a bit and only now thought to myself hey, maybe i should check how (easily) recreating my system actually is in case i ever need to do so. The issue i ran into was, of course, that the install media can't decrypt any secrets during nixos-install. Is there a way to supply a user or a previous host key to that or do i have to re-key everything? | 00:01:46 |
Valodim | Personally I find it's easiest to deploy a relatively blank nixos (e.g. just disk config), rekey, then do the full in install. Doesn't hurt to have new host keys once in a while, but ymmv | 06:35:11 |
Daniel RodrÃguez Rivero | If that is the intended usage, would not be SOPS simpler? It will work fine without the secrets, then you put them and run again to get the data decryted for real | 08:19:45 |
Valodim | agenix also "works fine" without secrets, the secret files just won't be there 🤷 | 08:25:52 |
Daniel RodrÃguez Rivero | then you don't need a relatively blank anything, no? | 08:28:16 |
Daniel RodrÃguez Rivero | just don't depend on secrets for your system to function | 08:28:33 |
Valodim | maybe I just misunderstood what you meant by "sops will work fine without the secrets". I'd think it behaves very similar to agenix in this regard | 08:33:54 |
kiwicutter | Yeah fair point tbh, as long as the secrets don't prevent the system from running itll be easy enough to rekey right after. | 08:42:17 |
kiwicutter | I guess the host keys will only be generated during a first startup though and not already during nixos-install? Else one could already check those and rekey right after the install.. | 08:43:32 |
Daniel RodrÃguez Rivero | As far as I know, they just put empty files in places, instead of failing. Is that what agenix does too? | 08:54:16 |
Daniel RodrÃguez Rivero | But in order to rekey, you need to do that in an environment where the secrets are available. No? so you can't do that in the host being built | 08:57:41 |
kiwicutter | As long as i have my "master" key i can just go about and re-key everything no problem or am i missing something | 14:50:10 |
| Gaël joined the room. | 22:27:10 |
| Charles left the room. | 22:30:10 |
12 Mar 2025 |
xored | Hi everyone, I've been trying to use the path option to decrypt a secret to $home/.config/ntfy/client.yaml, but is not working, my best guess is that is not being evaluated? | 02:53:43 |
elikoga | Are you using straight up "$home"? Either that's not evaluated or placed at the home of the agenix activation script user (probably root?) | 02:56:11 |