!XLCFfvFhUkYwOMLbVx:nixos.org

agenix

323 Members
age-encrypted secrets for NixOS https://github.com/ryantm/agenix/93 Servers

Load older messages


SenderMessageTime
25 Feb 2025
@horigome:matrix.org@horigome:matrix.orge.g., in the activation stage19:38:11
@horigome:matrix.org@horigome:matrix.org🤦20:05:13
@horigome:matrix.org@horigome:matrix.orgFigured it out.20:05:19
@horigome:matrix.org@horigome:matrix.orgJust some permission bs20:05:28
26 Feb 2025
@danielo515:matrix.orgDaniel Rodríguez Rivero joined the room.19:13:42
@danielo515:matrix.orgDaniel Rodríguez RiveroHello everyone. I want to start managing my dotfile secrets with agenix, but I don't want to be tied to host specific keys. Is there any way I can do an initial bootstrap using a passphrase that sets the required infrastructure and then do the normal agenix flow?19:31:13
1 Mar 2025
@Valodim:stratum0.orgValodim joined the room.16:10:47
3 Mar 2025
@bonus:bonusplay.plBonus joined the room.22:50:52
6 Mar 2025
@alarsyo:alarsyo.netalarsyo joined the room.02:33:24
@frankingfish45:matrix.org@frankingfish45:matrix.org joined the room.04:48:43
@frankingfish45:matrix.org@frankingfish45:matrix.org removed their display name frankingfish45.08:07:56
@frankingfish45:matrix.org@frankingfish45:matrix.org left the room.08:08:38
7 Mar 2025
@qyriad:katesiria.orgQyriad changed their display name from Qyriad to qyriad.16:58:25
8 Mar 2025
@laurent:matrix.fdn.frlaurentHi there, Im new to the nixos ecosystem. I asked a question on the agenix discussion page https://github.com/ryantm/agenix/discussions/312, regarding agenix asking for my passkey passphrase on boot, with no timeout.nixos logo will spin forever unless i press esc at the right time(otherwise if i press too late, boot sequence is basically frozen). Any tip on how to avoid this without having a private key without a passphrase?06:08:59
@k900:0upti.meK900That's not really the intended use cass06:19:48
@k900:0upti.meK900You probably want full disk encryption 06:20:00
@laurent:matrix.fdn.frlaurent
In reply to @k900:0upti.me
That's not really the intended use cass
What do you mean? What is the intended use case? My understanding is just to encrypt password, tokens... with my private ssh key so that i can put my nixos config on github
06:23:43
@k900:0upti.meK900Yes, but it's not really designed to be used interactively06:41:00
@k900:0upti.meK900The way you're trying to use it06:41:04
@k900:0upti.meK900If you want that kind of thing, you should encrypt to a secret like your machine's SSH host key06:41:21
@k900:0upti.meK900That is stored on an encrypted disk06:41:29
@horigome:matrix.org@horigome:matrix.org left the room.06:57:30
@laurent:matrix.fdn.frlaurent
In reply to @k900:0upti.me
If you want that kind of thing, you should encrypt to a secret like your machine's SSH host key
Hum I think I wasnt clear sorry. I dont want the boot sequence to be interactive and asking for my ssh host key password. Maybe i didnt set up my ssh key good enough with nix?
07:06:43
@k900:0upti.meK900You don't want any password prompts at all?07:07:03
@k900:0upti.meK900Then you just need to encrypt to your SSH host key07:07:16
@k900:0upti.meK900Not your user key07:07:19
@laurent:matrix.fdn.frlaurent
In reply to @k900:0upti.me
You don't want any password prompts at all?
I dont want a password prompt hanging on the boot sequence as it freezes my machine, and the "asking for password prompt" is hidden behind the nixos booting logo. Im used to only have one ssh key with other linux distrib,so i prob didnt setup things properly by having the same key for host and user. Ill investigate!
07:16:23
@k900:0upti.meK900The host key is not something you need to manually create07:16:52
@k900:0upti.meK900 It's created when you start sshd for the first time, in /etc/ssh/sshhostkey_ed25519 07:17:05
@laurent:matrix.fdn.frlaurentAhh thx, i wasnt even aware of this folder! I put my key in my ~/.ssh as for other linux! 07:20:11

Show newer messages


Back to Room ListRoom Version: 6