!XLCFfvFhUkYwOMLbVx:nixos.org

agenix

358 Members
age-encrypted secrets for NixOS https://github.com/ryantm/agenix/91 Servers

Load older messages


SenderMessageTime
23 Mar 2023
@oddlama:matrix.orgoddlamaThe project is mostly complete, so I'd expect updates finished.15:56:10
@oddlama:matrix.orgoddlama * The project is mostly complete, so I'd expect updates only rarely.15:56:16
24 Mar 2023
@hannes4761:matrix.orghannes4761 joined the room.21:49:24
25 Mar 2023
@amardeeps:matrix.orgamardeeps joined the room.04:45:12
26 Mar 2023
@rbutani:matrix.orgrbutani joined the room.00:31:32
@redstone-menace:matrix.orgredstone-menace Can you either define agenix secrets outside of a nixosConfiguration / homeManagerConfiguration or access secrets within them outside of the system config they were defined? 13:58:02
@ryantm:matrix.orgryantmSure, you can make a module that you use in multiple nixosConfigurations.13:59:25
28 Mar 2023
@qverkk:matrix.orgqverkk joined the room.18:52:15
@qverkk:matrix.orgqverkkimage.png
Download image.png
18:53:09
@qverkk:matrix.orgqverkkyo, is this correct? 🤣18:53:09
@qverkk:matrix.orgqverkkcan we use keepass with agenix?18:53:19
@ryantm:matrix.orgryantmHallucinations18:56:22
@qverkk:matrix.orgqverkkyeah thats waht i thought, couldnt find anything about this on github XD18:57:54
@qverkk:matrix.orgqverkkaltho it would be nice to use an existing keepassxc db for nixos secrets18:58:20
@raphi:tapesoftware.netraphichatgpt output is wrong unless proven otherwise19:01:10
29 Mar 2023
@jeroen:simonetti.nljeroen does anyone have a hint as to why my agenix does not decrypt secrets at boot, but works fine after a rebuild switch? 16:39:16
@cole-h:matrix.orgcole-hHard to tell without logs but sounds like a secret path may not be available at boot16:41:46
@jeroen:simonetti.nljeroen what kind of logs would I need to look at? I still have the system at fresh boot state, so /run/agenix is empty 16:42:34
@cole-h:matrix.orgcole-h The activation logs should be in dmesg / journalctl -k somewhere 16:43:05
@jeroen:simonetti.nljeroen age secret files are under /etc/nixos so should be available 16:43:28
@jeroen:simonetti.nljeroenhmm, I think it's cause the system has it's ssh keys somewhere else16:44:22
@cole-h:matrix.orgcole-hThere's an option for that IIRC.16:46:02
@jeroen:simonetti.nljeroen

the ssh host keys are on a persistant zfs volume which is not yet available at decrypt time ...

[agenix] WARNING: config.age.identityPaths entry /persist/system/etc/ssh/ssh_host_ed25519_key not present!
16:46:11
@jeroen:simonetti.nljeroen *

the ssh host keys are on a persistant zfs volume filesystem which is not yet available at decrypt time ...

[agenix] WARNING: config.age.identityPaths entry /persist/system/etc/ssh/ssh_host_ed25519_key not present!
16:47:44
@cole-h:matrix.orgcole-hMight be able to get it to work by marking that fs as neededForBoot (a NixOS option)16:48:37
@jeroen:simonetti.nljeroentnx, I'll give that a go16:54:56
30 Mar 2023
@jeroen:simonetti.nljeroenthat actually fixed it15:19:08
31 Mar 2023
@j0lol:the-apothecary.clubj0 joined the room.18:42:05
5 Apr 2023
@craige:mcwhirter.iocraige joined the room.00:04:43
* @craige:mcwhirter.iocraige waves00:06:14

Show newer messages


Back to Room ListRoom Version: 6