Add agenix-rekey module + rekey config back to lazyworkhorse
agenix-rekey auto-re-encrypts secrets per host at build time: - Encrypted once in git with master identity - Re-encrypted for each host using their SSH host key - No manual multi-recipient encryption needed
This commit is contained in:
@@ -12,5 +12,7 @@ in
|
||||
"home_wifi.age".publicKeys = authorizedKeys;
|
||||
"lazyworkhorse_host_ssh_key.age".publicKeys = authorizedKeys;
|
||||
"n8n_ssh_key.age".publicKeys = authorizedKeys;
|
||||
"builder_key.age".publicKeys = authorizedKeys;
|
||||
"builder_key.age".publicKeys = authorizedKeys ++ [
|
||||
keys.hosts.uConsole.bootstrap
|
||||
];
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user