!XLCFfvFhUkYwOMLbVx:nixos.org

agenix

322 Members
age-encrypted secrets for NixOS https://github.com/ryantm/agenix/93 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
6 Jan 2025
@jeroen:simonetti.nl@jeroen:simonetti.nl left the room.16:40:02
12 Jan 2025
@strutztm:strutztm.de@strutztm:strutztm.de joined the room.00:22:06
19 Jan 2025
@wiiplayer2:matrix.orgWaldemar Tomme (they/them) changed their display name from Waldemar Tomme to Waldemar Tomme (they/them).08:17:06
25 Jan 2025
@fwam:femdom.solutionsfwam changed their profile picture.04:32:11
28 Jan 2025
@fwam:femdom.solutionsfwam changed their profile picture.17:15:04
@howlymowly:matrix.orgThomas m changed their display name from howlymowly to Thomas m.19:26:50
3 Feb 2025
@cameronraysmith:matrix.orgcameronraysmith joined the room.05:06:26
@guhou:matrix.orgGus joined the room.06:05:32
@guhou:matrix.orgGus Anyone have good patterns for decrypting "secrets" for eval-time configuration? E.g. I want to set services.caddy.virtualHosts.foo.hostName = "foo.${myTailnet}". I don't care about myTailnet being in the nix store but I would prefer that it's not plaintext in my git repo 06:13:21
@guhou:matrix.orgGusI saw that maybe scalpel can solve this?06:13:42
@guhou:matrix.orgGuswondering if there is a straightforward way that people recommend :) 06:14:03
9 Feb 2025
@lordkekz:matrix.orgLordKekz Nix doesn't have eval-time secrets. But if you just want to avoid putting some variables in a public repo, you can make a separate private repo on your git forge of choice and add it as a flake input.
You will then need to provide credentials to the private repo, e.g. via ~/.config/nix/nix.conf.
22:21:01
@aliarokapis:matrix.orgAlexandros LiarokapisRedacted or Malformed Event23:23:30
@aliarokapis:matrix.orgAlexandros Liarokapis* If doing that be careful if you are in a multi-user setup23:23:40

Show newer messages


Back to Room ListRoom Version: 6