NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

.sops.yaml (867B)


      1 # sops configuration for ~/NixDaemon (sops-nix). One age identity, used by
      2 # the user (~/.config/sops/age/keys.txt, where the sops CLI looks) and by the
      3 # system at activation (/var/lib/sops-nix/key.txt, a root-only copy of it).
      4 #
      5 #   sops secrets/secrets.yaml            edit (decrypts in $EDITOR, re-encrypts on save)
      6 #   sops -d secrets/secrets.yaml         print decrypted
      7 #   sops updatekeys secrets/secrets.yaml re-encrypt after changing the keys below
      8 #
      9 # To add a second machine or key: generate its age key, add the public key to
     10 # `keys` and the rule, then `sops updatekeys` every file.
     11 keys:
     12   - &daemonsec age1pu5wcvqqh92xr6ces8zmj4xvs52v7yfm4jsfcxm3z82a32u9n97qesldfv
     13 creation_rules:
     14   - path_regex: secrets/.*   # any file under secrets/, incl. whole-file (binary) secrets like secrets/floorp/user.js
     15     key_groups:
     16       - age:
     17           - *daemonsec