thermograph/infra/.sops.yaml
Emi Griffith ae1d9bb534 Subtree-merge thermograph-infra (origin/main) into infra/
git-subtree-dir: infra
git-subtree-mainline: d6df04eab2
git-subtree-split: 99b4b3f78d
2026-07-22 22:01:11 -07:00

14 lines
783 B
YAML

# SOPS creation rules — how `sops <file>` encrypts secrets in this repo.
#
# Every deploy/secrets/*.yaml is encrypted to the age recipient below (values only;
# keys stay readable for clean diffs). The matching PRIVATE key is NEVER in the repo
# — it lives at ~/.config/sops/age/keys.txt on the operator's machine and at
# /etc/thermograph/age.key on each host that renders secrets at deploy time.
#
# Rotating the age identity itself: add the new recipient here, run
# sops updatekeys deploy/secrets/*.yaml
# to re-encrypt to both, distribute the new private key, then drop the old recipient
# and updatekeys again. See deploy/secrets/README.md.
creation_rules:
- path_regex: ^deploy/secrets/.*\.yaml$
age: age1xx4dzs0dxlwvkv9sjuqzsphl7lfrxannkfken374yu2qvvcte9sqzktqt2