!XLCFfvFhUkYwOMLbVx:nixos.org

agenix

379 Members
age-encrypted secrets for NixOS https://github.com/ryantm/agenix/99 Servers

Load older messages


SenderMessageTime
12 Jul 2023
@moots:matrix.orgmootsSince j both need the secrets in the Terraform rendered files in the machines im Plannung to build aswell which get crested by terranix19:52:07
@moots:matrix.orgmoots* Since j both need the secrets in the Terraform rendered files and n the machines im planning to build which get crested by terranix19:52:40
@moots:matrix.orgmoots * Since j both need the secrets in the Terraform rendered files and n the machines im planning to build which get created by terranix19:53:35
@kranzes:matrix.orgIlan Joselevich (Kranzes) Get agenix and nixos out the picture, they're not relevant to this. You should look into just encrypting your tfvars file 19:53:49
@moots:matrix.orgmootsi dont neccessairly need to encrypt the tfvars files, but the different ssh keys and providers private keys with close to automatic rekeying for every user 19:55:33
@moots:matrix.orgmoots * i dont neccessairly need to encrypt the tfvars files, but the different ssh keys and providers private keys with close to automatic rekeying for every user (of my private repo)19:55:58
@moots:matrix.orgmoots * i dont neccessairly need to encrypt the tfvars files, but the different ssh keys and providers private keys with close to automatic rekeying for every user (of my private repo). so that i can keep everything(literally everything) in a monorepo using josh19:56:27
@moots:matrix.orgmootslets see if i can figure out how to run age in the nix build before the terranix terraform part gets rendered20:01:59
@moots:matrix.orgmootsso the decrypted part is accessible from the nix store in terranix20:02:41
@kranzes:matrix.orgIlan Joselevich (Kranzes)Idk if this is helpful but look at this https://github.com/kranzes/tf-infra20:17:07
@moots:matrix.orgmoots
In reply to @kranzes:matrix.org
Idk if this is helpful but look at this https://github.com/kranzes/tf-infra
yep i think runCommand will work
20:47:58
@moots:matrix.orgmootsthanks!20:48:03
@adam:valkor.netadamcstephens joined the room.21:43:53
13 Jul 2023
@moots:matrix.orgmoots
In reply to @moots:matrix.org
yep i think runCommand will work
does someone maybe have a quicktip on how to access the ssh kyes from the home folder ?
14:28:57
@moots:matrix.orgmoots
In reply to @moots:matrix.org
yep i think runCommand will work
*

does someone maybe have a quicktip on how to access the ssh kyes from the home folder ?
++ /nix/store/r9hjvsggi230b413hs0v6zr88d50jx3p-agenix-0.13.0/bin/agenix -d oci.pem.age
config-tf> warning: '/nix/var/nix' does not exist, so Nix will use '/homeless-shelter/.local/share/nix/root' as a chroot store
config-tf> No identity found to decrypt oci.pem.age. Try adding an SSH key at /homeless-shelter/.ssh/id_rsa or /homeless-shelter/.ssh/id_ed25519 or using the --identity flag to specify a file.
example how i use it rn in the flake

"${agenix.packages.${system}.agenix}/bin/agenix -d  ${builtins.baseNameOf value.file} > $out/${builtins.replaceStrings [".age"] [""] (builtins.baseNameOf value.file)}") 
14:30:06
@moots:matrix.orgmoots actually i guess its impossible in pure mode hmm 14:35:18
@rigille:matrix.orgRígille S. B. Menezes joined the room.17:26:27
@rigille:matrix.orgRígille S. B. MenezesHey, is it possible to use agenix without nix modules?17:27:23
@ryantm:matrix.orgryantmWhat do you mean by nix modules?17:55:01
@rigille:matrix.orgRígille S. B. MenezesSorry I meant NixOS modules17:55:30
@rigille:matrix.orgRígille S. B. Menezes set a profile picture.17:57:15
@rigille:matrix.orgRígille S. B. MenezesFrom what I read in the documentation it looks like agenix is only meant to be used with NixOS17:58:07
@ryantm:matrix.orgryantmIt also works with HomeManager but that currently has no docs.18:56:45
@rigille:matrix.orgRígille S. B. MenezesOh I see18:57:41
14 Jul 2023
@cole-h:matrix.orgcole-h changed their display name from cole-h to cole-h (back 1 Aug).23:51:20
25 Jul 2023
@federicodschonborn:matrix.orgFederico Damián Schonborn changed their profile picture.01:57:13
@vika:fireburn.ruVika (she/her) joined the room.13:10:25
26 Jul 2023
@krustykonez:beeper.comkrustyjonez joined the room.13:02:42
27 Jul 2023
@ribosomerocker:matrix.orgribosomerocker joined the room.03:02:40
@charles:computer.surgeryCharles ⚡️ joined the room.05:36:13

Show newer messages


Back to Room ListRoom Version: 6