.sops.yaml (867B)
1 # sops configuration for ~/NixDaemon (sops-nix). One age identity, used by 2 # the user (~/.config/sops/age/keys.txt, where the sops CLI looks) and by the 3 # system at activation (/var/lib/sops-nix/key.txt, a root-only copy of it). 4 # 5 # sops secrets/secrets.yaml edit (decrypts in $EDITOR, re-encrypts on save) 6 # sops -d secrets/secrets.yaml print decrypted 7 # sops updatekeys secrets/secrets.yaml re-encrypt after changing the keys below 8 # 9 # To add a second machine or key: generate its age key, add the public key to 10 # `keys` and the rule, then `sops updatekeys` every file. 11 keys: 12 - &daemonsec age1pu5wcvqqh92xr6ces8zmj4xvs52v7yfm4jsfcxm3z82a32u9n97qesldfv 13 creation_rules: 14 - path_regex: secrets/.* # any file under secrets/, incl. whole-file (binary) secrets like secrets/floorp/user.js 15 key_groups: 16 - age: 17 - *daemonsec