# SOPS creation rules — how `sops ` encrypts secrets in this repo. # # Every deploy/secrets/*.yaml is encrypted to the age recipient below (values only; # keys stay readable for clean diffs). The matching PRIVATE key is NEVER in the repo # — it lives at ~/.config/sops/age/keys.txt on the operator's machine and at # /etc/thermograph/age.key on each host that renders secrets at deploy time. # # Rotating the age identity itself: add the new recipient here, run # sops updatekeys deploy/secrets/*.yaml # to re-encrypt to both, distribute the new private key, then drop the old recipient # and updatekeys again. See deploy/secrets/README.md. creation_rules: - path_regex: ^deploy/secrets/.*\.yaml$ age: age1xx4dzs0dxlwvkv9sjuqzsphl7lfrxannkfken374yu2qvvcte9sqzktqt2