!atvIbxHoEqNcAIxYpN:nixos.org

NixOS AWS

65 Members
17 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
28 Apr 2025
@notmycommit:notwork.indbalanSecrets are in vault or aws depending on the layer and they get populated on first boot in the config15:04:57
@adam:robins.wtfadamcstephensI wrote a simple module that will pull a secret down with the CLI given an ARN and some permissions. Creates a basic dir in /run to avoid storing them on disk22:51:20
@adam:robins.wtfadamcstephensAPI is roughly what you get from agenix22:51:47
@adam:robins.wtfadamcstephensWe do pull one secret during cloud-init, but otherwise try and keep it as simple as possible. Cloud init's main job is to discover the proper system store path, pull it, and switch to it, and a couple other imperative things about the system for PS1 and an env file. Our apps also now read their secrets directly on startup, so most secrets never get written outside memory.22:53:48
@kranzes:matrix.orgIlan Joselevich (Kranzes)
In reply to @adam:robins.wtf
I wrote a simple module that will pull a secret down with the CLI given an ARN and some permissions. Creates a basic dir in /run to avoid storing them on disk
Do you have this in a public repo somewhere?
23:04:17

Show newer messages


Back to Room ListRoom Version: 10