From a1a02a638acf2052bd10f49401c3a7796a40d45c Mon Sep 17 00:00:00 2001 From: Lillian-Violet Date: Sat, 4 Nov 2023 10:30:17 +0100 Subject: [PATCH] Figured out sops --- .sops.yaml | 8 +++++--- secrets/EDI-Lillian.yaml | 21 +++++++++++++++++++++ 2 files changed, 26 insertions(+), 3 deletions(-) create mode 100644 secrets/EDI-Lillian.yaml diff --git a/.sops.yaml b/.sops.yaml index 826efd6..b7b6799 100644 --- a/.sops.yaml +++ b/.sops.yaml @@ -3,9 +3,11 @@ # Also see https://github.com/Mic92/dotfiles/blob/master/nixos/.sops.yaml # for a more complex example. keys: - - &lillian age12e00qvf4shtmsfq3ujamyaa72pjvad2qhrxkvpl9hryrjvgxev4sjhmkxz + - &admin_lillian age12e00qvf4shtmsfq3ujamyaa72pjvad2qhrxkvpl9hryrjvgxev4sjhmkxz creation_rules: - path_regex: secrets/[^/]+\.(yaml|json|env|ini)$ key_groups: - age: - - *lillian \ No newline at end of file + - age: + - *admin_lillian +#Run the following command to create EDI-Lillian.yaml in the secrets folder: +# nix-shell -p sops --run "sops secrets/EDI-Lillian.yaml" \ No newline at end of file diff --git a/secrets/EDI-Lillian.yaml b/secrets/EDI-Lillian.yaml new file mode 100644 index 0000000..8a2082f --- /dev/null +++ b/secrets/EDI-Lillian.yaml @@ -0,0 +1,21 @@ +password: ENC[AES256_GCM,data:4EAU7m0RF3BWnIDdcRFkC+UcwcQ=,iv:s1gF8edUjatry3h/e5ZmBXLOEJO1iX8tiyuanzuJgJY=,tag:cicC8WzOnIhG8xIM09nrTw==,type:str] +sops: + kms: [] + gcp_kms: [] + azure_kv: [] + hc_vault: [] + age: + - recipient: age12e00qvf4shtmsfq3ujamyaa72pjvad2qhrxkvpl9hryrjvgxev4sjhmkxz + enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSB2R2hoVEwvOGV5ZnlNZHFa + SkNLUmdLc29kVEZqeXJDSmxmd2ZmNzFCREg0CklvbUpTMTJ4OXk3K1FOK013Y01m + Lzk3czVrek56N1VpZkJkeUlDaDM1VXcKLS0tIHJNTitsT3kwNHpzWkIxM0VsZmtP + eUZ6b09pYlRVWFBuUm1Ua2l6Z0dacW8KeQdAVsxXsDiDMtFA2koSpDsw7Ib63vA0 + GE/ubWDwwRc7wMPFGuofIe6TaDSFgtVXza+yo+i4y51+BOpwqxlYYA== + -----END AGE ENCRYPTED FILE----- + lastmodified: "2023-11-04T09:24:15Z" + mac: ENC[AES256_GCM,data:SoNQ2F2hye6l4B29dLOycZYNqdpluRWgsIj0ZJ5aanExBKq8REHyoXU11X+ItZkrHkyNHyDf1cpQSwyL0AMJG6KXn0z//hKuMijOF3AQ5fXgIu4vmutvpvvIQ/7rBxATsFq43QjIWHsSOOfi1HYpBRlDwc/oTCG9G//NzR9MqOo=,iv:uhZuK1wGPUbhby++T2diyleLWvGbFE+1HCuw0y73eTQ=,tag:lkWn+nYkGP0L0HyVjjYhCA==,type:str] + pgp: [] + unencrypted_suffix: _unencrypted + version: 3.8.1