15 Sep 2024 |
eyJhb | * Surely I'll not be the first one to do this. I have an existing setup of gpg keys, that I have backed up various places. I would like to use my gpg keys w/ agenix, in case I lose my ssh key. So, my thinking is to generate a age key, encrypt that with my gpg key, and place inside the repo. So in case I fuck something up, I can always decrypt it, and get access to my secrets. Does this sound 100% idiotic? Am I missing something? | 10:45:51 |
K900 | I don't think that sounds completely insane but also yuck | 10:46:19 |
eyJhb | Perfect, that's just what I was going for. | 10:47:23 |
eyJhb | I looked into using sops-nix, as I could use my gpg key there, but it feels very complex compared to what I need. agenix is just very very KISS in that regards.
The only other thing I considered, was adding a age key to my yubikey, but then I would need to have N times age secrets to manage. | 10:48:31 |
eyJhb | But granted, managing GPG keys is usually quite yuck. | 10:48:45 |