!XLCFfvFhUkYwOMLbVx:nixos.org

agenix

323 Members
age-encrypted secrets for NixOS https://github.com/ryantm/agenix/93 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
15 Sep 2024
@eyjhb:eyjhb.dkeyJhb Because you can't edit a file, which does not exists. Or rather, when you do agenix -e somefile.age, it will try to find the file in the secrets.nix file, and THEN IF it is in there, you can edit it. Otherwise you get a "attribute missing" error. 12:20:10
16 Sep 2024
@silentlurker:matrix.orgsilentlurker joined the room.19:56:14
17 Sep 2024
@titaniumtown:envs.nettitaniumtown joined the room.02:46:19
@titaniumtown:envs.nettitaniumtown hihihi, i am switching a ton of my stuff over to agenix. quick question though. How can I properly use a nix file as a secret. For instance. I have a wifi-passwords.nix, with declarations for each network and such. And I import it and such. But the thing is that I have to build my system, restart agenix. make sure the secret is there. and then uncomment the part referencing the secret. 02:47:53
@titaniumtown:envs.nettitaniumtown hihihi, i am switching a ton of my stuff over to agenix. quick question though. How can I properly use a nix file as a secret. For instance. I have a wifi-passwords.nix, with declarations for each network and such. And I import it and such. But the thing is that I have to build my system, restart agenix. make sure the secret is there. and then uncomment the part referencing the secret.

Is there a better way of doing this?
02:48:00
@titaniumtown:envs.nettitaniumtown hihihi, i am switching a ton of my stuff over to agenix. quick question though. How can I properly use a nix file as a secret. For instance. I have a wifi-passwords.nix, with declarations for each network and such. And I import it and such. But the thing is that I have to build my system, restart agenix. make sure the secret is there. and then uncomment the part referencing the secret.

Is there a better way of doing this?

There are some options that just require an actual string. not a file. I'm doing the best I can :(
02:48:47
@k900:0upti.meK900You could just use git-crypt or something for those04:53:37
@k900:0upti.meK900Since you're doing impure anyway04:53:41
@k900:0upti.meK900Or just gitignore the file04:53:45
@titaniumtown:envs.nettitaniumtown
In reply to@k900:0upti.me
Or just gitignore the file
yea I did that before, but then i have to copy around that nix file which is annoying, instead of having it in my dotfiles repo
13:35:08
@titaniumtown:envs.nettitaniumtown
In reply to@k900:0upti.me
You could just use git-crypt or something for those
haven't heard of git-crypt before. ty for the tip!
13:35:27
@titaniumtown:envs.nettitaniumtownseems this exists too! https://github.com/vlaci/git-agecrypt13:36:42
@titaniumtown:envs.nettitaniumtowncool stuff13:36:43
@titaniumtown:envs.nettitaniumtown
In reply to@titaniumtown:envs.net
seems this exists too! https://github.com/vlaci/git-agecrypt
I'm gonna switch to this. ty for the suggestion @K900!
13:41:53
@tomherbers:matrix.orgTom (deprecated) joined the room.21:06:23
18 Sep 2024
@rcambrj:matrix.orgrcambrj joined the room.07:19:12
@eyjhb:eyjhb.dkeyJhb Is it possible for agenix just to ignore files, when it doesn't have permission (the right keys) to decrypt them? I get this error chown: cannot access '/run/agenix.d/2/zrepl-chronos': No such file or directory 16:44:56
19 Sep 2024
@memegames99:matrix.org@memegames99:matrix.org joined the room.01:52:26

Show newer messages


Back to Room ListRoom Version: 6