tvl-depot/ops/secrets
Vincent Ambo 3a410a78df feat(ops/secrets): Make (encrypted) secrets part of the tree
Currently in NixOS configuration using agenix secrets there is no
build time validation of secret paths - things fail at runtime (system
activation).

To prevent that, this CL makes the secrets part of the tree based on
the same configuration file used by agenix itself.

This guards against:

* agenix secrets.nix definition for a non-existent file
* age.secrets value in a NixOS config for a non-existent secret

Change-Id: I5b191dcbd5b2522566ff7c38f8a988bbf7679364
2021-12-12 11:19:24 +03:00
..
.skip-subtree feat(ops/secrets): Bootstrap agenix secrets folder 2021-12-08 18:22:00 +00:00
besadii.age chore(ops/secrets): Reencrypt all secrets with sterni included 2021-12-11 18:51:36 +03:00
buildkite-agent-token.age chore(ops/secrets): Reencrypt all secrets with sterni included 2021-12-11 18:51:36 +03:00
buildkite-graphql-token.age chore(ops/secrets): Reencrypt all secrets with sterni included 2021-12-11 18:51:36 +03:00
clbot-ssh.age chore(ops/secrets): Reencrypt all secrets with sterni included 2021-12-11 18:51:36 +03:00
clbot.age chore(ops/secrets): Reencrypt all secrets with sterni included 2021-12-11 18:51:36 +03:00
default.nix feat(ops/secrets): Make (encrypted) secrets part of the tree 2021-12-12 11:19:24 +03:00
gerrit-queue.age chore(ops/secrets): Reencrypt all secrets with sterni included 2021-12-11 18:51:36 +03:00
grafana.age chore(ops/secrets): Reencrypt all secrets with sterni included 2021-12-11 18:51:36 +03:00
irccat.age chore(ops/secrets): Reencrypt all secrets with sterni included 2021-12-11 18:51:36 +03:00
nix-cache-priv.age chore(ops/secrets): Reencrypt all secrets with sterni included 2021-12-11 18:51:36 +03:00
nix-cache-pub.age chore(ops/secrets): Reencrypt all secrets with sterni included 2021-12-11 18:51:36 +03:00
owothia.age chore(ops/secrets): Reencrypt all secrets with sterni included 2021-12-11 18:51:36 +03:00
panettone.age chore(ops/secrets): Reencrypt all secrets with sterni included 2021-12-11 18:51:36 +03:00
README.md feat(ops/secrets): Bootstrap agenix secrets folder 2021-12-08 18:22:00 +00:00
secrets.nix feat(ops/secrets): add keys for sterni 2021-12-11 15:41:55 +00:00

TVL's deployment secrets, encrypted with agenix