!XLCFfvFhUkYwOMLbVx:nixos.org

agenix

359 Members
age-encrypted secrets for NixOS https://github.com/ryantm/agenix/91 Servers

Load older messages


SenderMessageTime
9 Jan 2026
@ivy:fargone.shIvyis that something people would want?08:02:56
@ivy:fargone.shIvyi have it working on darwin08:03:03
@Findus:stratum0.orgfindusI've read the source code a little and it seems like agenix also uses systemd to mount the secrets partition when sysusers are enabled (https://mynixos.com/nixpkgs/option/systemd.sysusers.enable), but when enabling that every user defined in the nix config must be a system user, dad did not work out for me08:50:17
@Findus:stratum0.orgfindushttps://github.com/ryantm/agenix/blob/fcdea223397448d35d9b31f798479227e80183f6/modules/age.nix#L28308:52:02
@whispers:catgirl.cloudwhispers [& it/fae]for what it's worth, it also uses the systemd service if userborn is used, which can handle both normal and system users12:59:21
@ivy:fargone.shIvyhow do you use agenix rekey over like ssh13:18:55
@ivy:fargone.shIvylike how can i do that "sanely"13:19:01
@k900:0upti.meK900Do you mean, like, with a key stored in a forwarded SSH agent?13:19:57
@ivy:fargone.shIvylike that13:20:16
@ivy:fargone.shIvybut i know that ssh agents can only sign not encrypt or decrypt13:20:25
@k900:0upti.meK900Yeah you can't13:20:39
@k900:0upti.meK900That's a design decision by the SSH agent13:20:45
@ivy:fargone.shIvyyes13:20:50
@ivy:fargone.shIvyso i wanna know what would be another thing i can forward over ssh to use agenix-rekey13:21:07
@k900:0upti.meK900You basically have to get your key onto the machine that you're running rekey on13:21:08
@k900:0upti.meK900There is no such thing13:21:13
@ivy:fargone.shIvyugh13:21:16
@ivy:fargone.shIvycan i forward ncsd from my yubikey over?13:21:29
@ivy:fargone.shIvylike a socket for it?13:21:31
@k900:0upti.meK900age only operates on local key files normally13:22:07
@k900:0upti.meK900You can do more things with plugins13:22:11
@k900:0upti.meK900But I'm not sure there is a plugin that will allow you to directly do that13:22:19
@ivy:fargone.shIvyyeah i mean with plugins sorry meant to clarify that13:22:24
@ivy:fargone.shIvylike for example im using age-plugin-yubikey13:22:32
@ivy:fargone.shIvyand i wonder if theres a way to forward my yubikey over ssh13:22:41
@k900:0upti.meK900I don't know what age-plugin-yubikey does13:23:17
@k900:0upti.meK900You could probably do horrible usbip things13:23:22
@k900:0upti.meK900At the very least13:23:26
@ivy:fargone.shIvyi think it uses pcscd13:23:30
@ivy:fargone.shIvyand might be possible to forward that13:23:41

Show newer messages


Back to Room ListRoom Version: 6