!XLCFfvFhUkYwOMLbVx:nixos.org

agenix

358 Members
age-encrypted secrets for NixOS https://github.com/ryantm/agenix/91 Servers

Load older messages


SenderMessageTime
24 Aug 2025
@crop_tech:matrix.orgcrop joined the room.15:55:21
@crop_tech:matrix.orgcrop i want to use agenix on a nixos system without channels (and flakes) i use npins to manage the inputs.
i followed the tutorial in the readme.
but when i try to use the agenix-cli i get the following error

agenix -e secret1.nix
Error:
   0: Failed to find config root

how can i solve this problem?
16:07:18
@k900:0upti.meK900Sounds like it can't find your secrets.nix?16:12:21
@crop_tech:matrix.orgcropthe secrets file is in the same folder where i am when i run the command16:27:15
@k900:0upti.meK900Not sure then16:28:02
@k900:0upti.meK900I can't even find that error message in the sources of agenix16:29:48
@crop_tech:matrix.orgcrop a forgot a line from the error message:
Location:
   src/cli.rs:216
16:31:50
@k900:0upti.meK900Uhh16:32:14
@k900:0upti.meK900Are you using ragenix or something?16:32:18
@k900:0upti.meK900I don't know what ragenix is doing but you should probably report that to ragenix16:32:36
@crop_tech:matrix.orgcropohhh not that i planned to16:32:56
@crop_tech:matrix.orgcropi use agenix-cli from nixpkgs16:34:04
@k900:0upti.meK900No idea what that is or how it's different16:34:47
@k900:0upti.meK900The original agenix tool is a shell script16:34:54
@k900:0upti.meK900That's in the agenix repo16:34:57
@crop_tech:matrix.orgcropyes now i use that (not from nixpkgs) and it works ... why is there a agenix-cli in nixpkgs that doesn't work? 😠16:43:32
@k900:0upti.meK900I don't know16:44:20
26 Aug 2025
@dawnofmidnight:catgirl.cloud@dawnofmidnight:catgirl.cloud joined the room.02:34:10
27 Aug 2025
@somasis:matrix.orgkylie joined the room.00:25:24
28 Aug 2025
@sbc64:matrix.orgsbc64 changed their profile picture.14:23:19
@redbeardy_mcgee:matrix.org@redbeardy_mcgee:matrix.org left the room.16:36:00
30 Aug 2025
@522_:catgirl.cloud@522_:catgirl.cloud changed their display name from 522 [it/its][ΘΔ] to 522 it/its ⛯ΘΔ.14:10:21
1 Sep 2025
@mfmcl:matrix.orgmike joined the room.17:43:07
3 Sep 2025
@ed209a:matrix.orged209 joined the room.19:18:26
@ed209a:matrix.orged209 I'm looking for ways to store build-time secrets using agenix, but it seems to be a bit tricky to do. is there an easy way to (potentially imperitively) decrypted a subset of secrets so they're available on the system before deploying/building images? 19:21:04
@k900:0upti.meK900Build-time secrets are basically always bad19:22:46
@k900:0upti.meK900Why do you want that?19:22:52
@ed209a:matrix.orged209 i should say deploy time... like how else do you give luks the key to use when provisioning a system? 19:23:26
@k900:0upti.meK900Can you explain what you're actually trying to do?19:23:46
@ed209a:matrix.orged209 the main use case is using nixos-anywhere to provision a system with luks 19:25:38

Show newer messages


Back to Room ListRoom Version: 6