Lemmy.one
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Jeezy@lemmy.world to NixOS@infosec.pubEnglish · 2 years ago

Providing Runtime Secrets to NixOS Services with Agenix

lgug2z.com

external-link
message-square
0
fedilink
11
external-link

Providing Runtime Secrets to NixOS Services with Agenix

lgug2z.com

Jeezy@lemmy.world to NixOS@infosec.pubEnglish · 2 years ago
message-square
0
fedilink
Providing Runtime Secrets to NixOS Services
lgug2z.com
external-link
In my last post, I shared how to get a working instance of Nitter deployed on NixOS, but requested advice on how to best automatically provision the guest_accounts.json runtime secret file on the target server. A number of folks reached out to me on Mastodon (thanks @vt52@ioc.exchange, @aynish@merveilles.town, @linus@schreibt.jetzt and @uep@octodon.social!) to suggest that I use agenix to copy encrypted files to the server and decrypt them in non-world readable directories, and then use systemd’s LoadCredentials option to make them available to the nitter service.
alert-triangle
You must log in or # to comment.

NixOS@infosec.pub

nixos@infosec.pub

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !nixos@infosec.pub

NixOS is a Linux distribution built on top of the Nix package manager. Its declarative configuration allows reliable system upgrades via several official channels of stability and size.

This community discusses NixOS, Nix, and everything related.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 2 users / day
  • 2 users / week
  • 1 user / month
  • 11 users / 6 months
  • 15 local subscribers
  • 1.09K subscribers
  • 80 Posts
  • 160 Comments
  • Modlog
  • mods:
  • PortugalSpaceMoon@infosec.pub
  • BE: 0.19.7
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org