!XLCFfvFhUkYwOMLbVx:nixos.org

agenix

382 Members
age-encrypted secrets for NixOS https://github.com/ryantm/agenix/99 Servers

Load older messages


SenderMessageTime
14 Apr 2023
@ambroisie:belanyi.frAmbroisie joined the room.16:37:16
15 Apr 2023
@nahfe:nahfe.xyzHerman left the room.20:53:01
16 Apr 2023
@ianluo001:matrix.orgian luo joined the room.02:27:57
@motiejus:jakstys.ltmotiejus joined the room.20:40:18
@motiejus:jakstys.ltmotiejus hi folks. I am using an agenix secret in boot.initrd.network.ssh.hostKeys, which is then picked up when generating initrd. However, initrd seems to be generated before the secrets are placed, erroring the build. Is there a way to place secrets before creating the initrd? I was looking for an "activation dependency" (TIL), but nixpkgs/nixos/modules/system/activation/top-level.nix seems to not allow such flexibility. Has anyone observed this before? 20:45:50
@motiejus:jakstys.ltmotiejus or in other words, has anyone used any agenix secret in boot.initrd.*? How? 20:46:27
@ryantm:matrix.orgryantmhttps://github.com/ryantm/agenix/blob/e64961977f60388dd0b49572bb0fc453b871f896/modules/age.nix#LL256C7-L256C45 If you learn which activation scripts set up the initrd. perhaps you can add a dep to them on agenixInstall21:07:13
@ryantm:matrix.orgryantmThere might be some issue with the specialfs dep. Have to make sure you don't have a circular dependency 21:07:59
17 Apr 2023
@genericnerdyusername:matrix.orgGenericNerdyUsername joined the room.22:56:42
18 Apr 2023
@jeroen:simonetti.nljeroen changed their display name from Jeroen Simonetti to jeroen.12:54:04
@jeroen:simonetti.nljeroen left the room.15:27:15
@jeroen:simonetti.nljeroen joined the room.16:04:35
19 Apr 2023
@pawning-cornmeal:matrix.org@pawning-cornmeal:matrix.org left the room.17:52:25
20 Apr 2023
@federicodschonborn:matrix.orgFederico Damián Schonborn changed their display name from Federico Damián Schonborn to Federico Schonborn.01:02:34
21 Apr 2023
@whentze:matrix.orgWanja Hentzehey, my PR https://github.com/ryantm/agenix/pull/175 is still open, could somebody give it a look?11:15:01
@whentze:matrix.orgWanja HentzeI didn't end up finding a way to regression test it, but I'd like the fix merged anyway. Is that alright?11:15:27
@mlyx:matrix.orgmlyx left the room.13:05:57
@ryantm:matrix.orgryantmMerged! Thanks 14:29:24
@ambroisie:belanyi.frAmbroisie Is there a way I can contribute to https://github.com/ryantm/agenix/pull/109 or would I have to create a new PR? 18:29:26
@ambroisie:belanyi.frAmbroisieI want to update it to fix some issues with it and try to get it merged 18:29:45
@cole-h:matrix.orgcole-hYou can ask them if they would give you push access to their repo, or you can ask if they would mind you opening a new PR based on their work.18:35:33
23 Apr 2023
@ambroisie:belanyi.frAmbroisieEnded up making a new PR from scratch, as my approach diverged too much from the original PRs for home-manager integration16:08:11
24 Apr 2023
@ambroisie:belanyi.frAmbroisie
In reply to @ambroisie:belanyi.fr
Ended up making a new PR from scratch, as my approach diverged too much from the original PRs for home-manager integration
Let me link to it in case people want to test drive it and/or review it
19:18:31
@ambroisie:belanyi.frAmbroisiehttps://github.com/ryantm/agenix/pull/18019:21:44
25 Apr 2023
@duponin:alternativebit.fr@duponin:alternativebit.frima_9063442.jpeg
Download ima_9063442.jpeg
15:25:56
@genericnerdyusername:matrix.orgGenericNerdyUsernameidk if this is more of a question for https://matrix.to/#/#tpm:nixos.org, but is it possible to store the agenix key in a tpm?21:38:30
@genericnerdyusername:matrix.orgGenericNerdyUsernameMaybe encrypt the keyfile using a separate key stored on the tpm?21:39:03
@ryantm:matrix.orgryantmThis might be possible, but we don't have any specific support for it.22:38:27
@genericnerdyusername:matrix.orgGenericNerdyUsernameis there some pre-activation hook i can use?22:38:55
@ryantm:matrix.orgryantm If you add an activationHook to system.activationScripts.agenixNewGeneration.deps then it should run before any agenix module code runs. 22:40:00

Show newer messages


Back to Room ListRoom Version: 6