!XLCFfvFhUkYwOMLbVx:nixos.org

agenix

329 Members
age-encrypted secrets for NixOS https://github.com/ryantm/agenix/95 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
22 Aug 2024
@uep:matrix.orguep

Secrets should be encrypted to several keys:

  • the ssh host public key of each system that needs it, to be decrypted at boot / activation
  • the user public key of each admin that needs to edit or change the config, such as when re-encrypting to add a new host

Note, in particular, that neither of these happens during build (but, yes, switch involves activation that should not involve a user key)

19:06:01

Show newer messages


Back to Room ListRoom Version: 6