!XLCFfvFhUkYwOMLbVx:nixos.org

agenix

359 Members
age-encrypted secrets for NixOS https://github.com/ryantm/agenix/92 Servers

Load older messages


SenderMessageTime
24 Aug 2025
@k900:0upti.meK900That's in the agenix repo16:34:57
@crop_tech:matrix.orgcropyes now i use that (not from nixpkgs) and it works ... why is there a agenix-cli in nixpkgs that doesn't work? 😠16:43:32
@k900:0upti.meK900I don't know16:44:20
26 Aug 2025
@dawnofmidnight:catgirl.cloud@dawnofmidnight:catgirl.cloud joined the room.02:34:10
27 Aug 2025
@somasis:matrix.orgkylie joined the room.00:25:24
28 Aug 2025
@sbc64:matrix.orgsbc64 changed their profile picture.14:23:19
@redbeardy_mcgee:matrix.org@redbeardy_mcgee:matrix.org left the room.16:36:00
30 Aug 2025
@522_:catgirl.cloud@522_:catgirl.cloud changed their display name from 522 [it/its][ΘΔ] to 522 it/its ⛯ΘΔ.14:10:21
1 Sep 2025
@mfmcl:matrix.orgmike joined the room.17:43:07
3 Sep 2025
@ed209a:matrix.orged209 joined the room.19:18:26
@ed209a:matrix.orged209 I'm looking for ways to store build-time secrets using agenix, but it seems to be a bit tricky to do. is there an easy way to (potentially imperitively) decrypted a subset of secrets so they're available on the system before deploying/building images? 19:21:04
@k900:0upti.meK900Build-time secrets are basically always bad19:22:46
@k900:0upti.meK900Why do you want that?19:22:52
@ed209a:matrix.orged209 i should say deploy time... like how else do you give luks the key to use when provisioning a system? 19:23:26
@k900:0upti.meK900Can you explain what you're actually trying to do?19:23:46
@ed209a:matrix.orged209 the main use case is using nixos-anywhere to provision a system with luks 19:25:38
@ed209a:matrix.orged209 * the main use case is using nixos-anywhere to provision a system with luks (using disko) 19:26:16
@ed209a:matrix.orged209 * the main use case is using nixos-anywhere to provision a system with luks (using disko) 19:26:27
@ed209a:matrix.orged209I'm certainly open to a better way. the secret is only needed when creating the luks volume, and then is unecessary/not stored19:27:16
@k900:0upti.meK900I feel like this is a nixos-anywhere problem19:27:47
@k900:0upti.meK900As in, the key should be provisioned by nixos-anywhere19:27:54
@k900:0upti.meK900Because it's what's doing the installing19:28:03
@k900:0upti.meK900 I don't know if it can actually do that 19:28:14
@k900:0upti.meK900But I know it is too early for agenix to do anything19:28:25
@ed209a:matrix.orged209
In reply to @k900:0upti.me
I don't know if it can actually do that
there is a mechanism for this
19:28:25
@k900:0upti.meK900(and same for other agenix shaped tools)19:28:41
@ed209a:matrix.orged209 found it, its --disk-encryption-keys... I guess I can manually decrypt secrets but would be cool if you could have it automatically done during deployment 19:30:52
@ed209a:matrix.orged209 * found it, its --disk-encryption-keys is the nixos-anywhere flag... I guess I can manually decrypt secrets but would be cool if you could have it automatically done during deployment 19:33:43
4 Sep 2025
@curious_cuttlefish:matrix.orgcurious_cuttlefish joined the room.04:41:16
8 Sep 2025
@inayet:matrix.orgInayet set a profile picture.02:15:48

Show newer messages


Back to Room ListRoom Version: 6