Skip to content

refactor: simplify recipient reports and schedule rules migration - #425

Open
ryantm wants to merge 1 commit into
feature/issue143-rekey-filefrom
refactor/issue406-cli-scope
Open

ryantm wants to merge 1 commit into
feature/issue143-rekey-filefrom
refactor/issue406-cli-scope

Conversation

@ryantm

@ryantm ryantm commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Retain agenix --check as a check for SSH recipient drift, and simplify extra-recipient output to the stanza type and short tag. Remove best-effort key reconstruction from Nix source text, which made output depend on whether keys were literal, imported, or computed. Missing recipients still display their configured keys. Help and reference text describe the limited scope; OpenSSH and GNU sed remain required.

Migrate the example and ordinary tests to agenix-rules.nix and AGENIX_RULES, retaining dedicated compatibility coverage. Propose retaining deprecated discovery throughout 0.19.x and removing it in 0.20.0 after a 0.19.0 release-note announcement. If that announcement is delayed, the plan requires postponing removal. Explicit AGENIX_RULES=secrets.nix remains supported.

Based on #424 and its documented dependencies; none have been merged. This PR records the migration policy but does not publish a release or remove compatibility.

Validation: package CLI/shellcheck, rules/plugin/encryption checks, the NixOS failure-safety VM after migrating its rules fixture, all-system test-flake evaluation, and the documentation build. The checker test verifies a short extra tag even when the full key remains literal in the rules.

Closes #406.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant