!XLCFfvFhUkYwOMLbVx:nixos.org

agenix

329 Members
age-encrypted secrets for NixOS https://github.com/ryantm/agenix/95 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
15 Sep 2024
@eyjhb:eyjhb.dkeyJhb * Surely I'll not be the first one to do this. I have an existing setup of gpg keys, that I have backed up various places. I would like to use my gpg keys w/ agenix, in case I lose my ssh key. So, my thinking is to generate a age key, encrypt that with my gpg key, and place inside the repo. So in case I fuck something up, I can always decrypt it, and get access to my secrets. Does this sound 100% idiotic? Am I missing something?10:45:51
@k900:0upti.meK900 I don't think that sounds completely insane but also yuck 10:46:19
@eyjhb:eyjhb.dkeyJhbPerfect, that's just what I was going for. 10:47:23
@eyjhb:eyjhb.dkeyJhbI looked into using sops-nix, as I could use my gpg key there, but it feels very complex compared to what I need. agenix is just very very KISS in that regards. The only other thing I considered, was adding a age key to my yubikey, but then I would need to have N times age secrets to manage. 10:48:31
@eyjhb:eyjhb.dkeyJhbBut granted, managing GPG keys is usually quite yuck.10:48:45

Show newer messages


Back to Room ListRoom Version: 6