!XLCFfvFhUkYwOMLbVx:nixos.org

agenix

358 Members
age-encrypted secrets for NixOS https://github.com/ryantm/agenix/91 Servers

Load older messages


SenderMessageTime
4 Jan 2026
@jappie:jappie.devjappie changed their display name from jasper to jappie.10:59:43
8 Jan 2026
@pltrz_:matrix.orgpltrz set a profile picture.23:50:06
9 Jan 2026
@pltrz_:matrix.orgpltrz changed their profile picture.00:00:37
@ivy:fargone.shIvy joined the room.05:43:24
@ivy:fargone.shIvyi think ive implemented restarting units like sops-nix?08:02:47
@ivy:fargone.shIvyis that something people would want?08:02:56
@ivy:fargone.shIvyi have it working on darwin08:03:03
@Findus:stratum0.orgfindusI've read the source code a little and it seems like agenix also uses systemd to mount the secrets partition when sysusers are enabled (https://mynixos.com/nixpkgs/option/systemd.sysusers.enable), but when enabling that every user defined in the nix config must be a system user, dad did not work out for me08:50:17
@Findus:stratum0.orgfindushttps://github.com/ryantm/agenix/blob/fcdea223397448d35d9b31f798479227e80183f6/modules/age.nix#L28308:52:02
@whispers:catgirl.cloudwhispers [& it/fae]for what it's worth, it also uses the systemd service if userborn is used, which can handle both normal and system users12:59:21
@ivy:fargone.shIvyhow do you use agenix rekey over like ssh13:18:55
@ivy:fargone.shIvylike how can i do that "sanely"13:19:01
@k900:0upti.meK900Do you mean, like, with a key stored in a forwarded SSH agent?13:19:57
@ivy:fargone.shIvylike that13:20:16
@ivy:fargone.shIvybut i know that ssh agents can only sign not encrypt or decrypt13:20:25
@k900:0upti.meK900Yeah you can't13:20:39
@k900:0upti.meK900That's a design decision by the SSH agent13:20:45
@ivy:fargone.shIvyyes13:20:50
@ivy:fargone.shIvyso i wanna know what would be another thing i can forward over ssh to use agenix-rekey13:21:07
@k900:0upti.meK900You basically have to get your key onto the machine that you're running rekey on13:21:08
@k900:0upti.meK900There is no such thing13:21:13
@ivy:fargone.shIvyugh13:21:16
@ivy:fargone.shIvycan i forward ncsd from my yubikey over?13:21:29
@ivy:fargone.shIvylike a socket for it?13:21:31
@k900:0upti.meK900age only operates on local key files normally13:22:07
@k900:0upti.meK900You can do more things with plugins13:22:11
@k900:0upti.meK900But I'm not sure there is a plugin that will allow you to directly do that13:22:19
@ivy:fargone.shIvyyeah i mean with plugins sorry meant to clarify that13:22:24
@ivy:fargone.shIvylike for example im using age-plugin-yubikey13:22:32
@ivy:fargone.shIvyand i wonder if theres a way to forward my yubikey over ssh13:22:41

Show newer messages


Back to Room ListRoom Version: 6