!XLCFfvFhUkYwOMLbVx:nixos.org

agenix

365 Members
age-encrypted secrets for NixOS https://github.com/ryantm/agenix/96 Servers

Load older messages


SenderMessageTime
16 Jan 2023
@ctx:kungfu-g.ripREASON...UNKNOWNIs there any strategy for setting secret ownership for services with DynamicUser=true03:23:31
@ctx:kungfu-g.ripREASON...UNKNOWNOh I guess the loadcredential business03:28:25
18 Jan 2023
@fabianhjr:matrix.orgFabián Heredia joined the room.03:56:10
27 Jan 2023
@ixsruc2ds59m8mnfvtifm:lolispace.moeCIA Penaiple joined the room.08:09:57
@da-ko:matrix.orgacire left the room.12:04:40
29 Jan 2023
@muirrum:matrix.org@muirrum:matrix.org left the room.15:52:04
30 Jan 2023
@ryantm:matrix.orgryantmAnyone itching to use agenix on nix-darwin? https://github.com/ryantm/agenix/pull/141 seems ready to merge to me, but I don't have hardware to test.02:29:05
@mikroskeem:d0.eeMarkcool, will try it out11:17:05
@ixsruc2ds59m8mnfvtifm:lolispace.moeCIA Penaiple changed their display name from t.A.T.u. to Zarah.11:39:23
@ixsruc2ds59m8mnfvtifm:lolispace.moeCIA Penaiple changed their profile picture.11:40:12
@ixsruc2ds59m8mnfvtifm:lolispace.moeCIA Penaiple changed their display name from Zarah to lollypop.12:34:36
@ixsruc2ds59m8mnfvtifm:lolispace.moeCIA Penaiple changed their profile picture.12:35:21
@ixsruc2ds59m8mnfvtifm:lolispace.moeCIA Penaiple changed their display name from lollypop to Dante's baby girl.12:48:51
@jeroen:simonetti.nljeroen afaik /run is disk-backed storage and not (as is the case with linux) a memoryfs
that's probably something to keep in mind
13:07:39
@ixsruc2ds59m8mnfvtifm:lolispace.moeCIA Penaiple changed their display name from Dante's baby girl to CIA Penaiple.13:08:59
@ixsruc2ds59m8mnfvtifm:lolispace.moeCIA Penaiple changed their profile picture.13:09:38
@jeroen:simonetti.nljeroen * afaik /run is disk-backed storage and not (as is the case with linux) a ramfs
that's probably something to keep in mind
13:13:38
@jeroen:simonetti.nljeroen * afaik /run is disk-backed storage and not (as is the case with linux) a (unswappable) ramfs
that's probably something to keep in mind
13:13:48
31 Jan 2023
@maralorn:maralorn.demaralorn joined the room.03:11:10
@ixsruc2ds59m8mnfvtifm:lolispace.moeCIA Penaiple removed their profile picture.12:48:03
@ixsruc2ds59m8mnfvtifm:lolispace.moeCIA Penaiple removed their display name CIA Penaiple.12:50:04
@ixsruc2ds59m8mnfvtifm:lolispace.moeCIA Penaiple left the room.12:51:06
@maralorn:maralorn.demaralornIs there a recommended way to use agenix with home-manager?18:44:02
@ryantm:matrix.orgryantmNo, not yet. The home-manager use case is still a bit foreign to me. I'm guessing everyone who wants this has their home-manager config unified with their OS config.18:47:49
@ryantm:matrix.orgryantmWe just merged support for nix-darwin into agenix! https://github.com/ryantm/agenix/pull/14118:48:38
@maralorn:maralorn.demaralorn
In reply to @ryantm:matrix.org
No, not yet. The home-manager use case is still a bit foreign to me. I'm guessing everyone who wants this has their home-manager config unified with their OS config.
Probably makes sense.
19:13:45
@ryantm:matrix.orgryantmSay your home-manager config is stored in your home directory, and decrypted via a key that your user knows, then that isn't much better than storing the files unecrypted in your home config, except that the encrypted files mean you could consider publishing your dotfiles.19:16:35
@cole-h:matrix.orgcole-h
In reply to @ryantm:matrix.org
We just merged support for nix-darwin into agenix! https://github.com/ryantm/agenix/pull/141
Woot! 🎉
The only "issue" (for me) is that now my config depends on nix-darwin, despite not owning any apple devices :P But that's extremely minor
20:31:01
@ryantm:matrix.orgryantm
In reply to @cole-h:matrix.org
Woot! 🎉
The only "issue" (for me) is that now my config depends on nix-darwin, despite not owning any apple devices :P But that's extremely minor
Hmm yeah. This seems like a general flakes problem.
20:49:42
@cole-h:matrix.orgcole-h We could do something like subflakes, but I'm not sure it's worth the effort at this point, when the cost is "only" a few megabytes of source that goes unused 20:50:17

Show newer messages


Back to Room ListRoom Version: 6