Skip to content

Add a tested secret-generation workflow with agenix-rekey - #450

Open
ryantm wants to merge 1 commit into
mainfrom
doc/issue236-secret-generation
Open

ryantm wants to merge 1 commit into
mainfrom
doc/issue236-secret-generation

Conversation

@ryantm

@ryantm ryantm commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Provides a concrete bootstrap workflow for #236 using agenix-rekey's existing generator options. The reusable example defines a random token and an Ed25519 key generator with a public-key sidecar, and works with NixOS and Home Manager. The guide covers missing ciphertext, administrator and target identities, separate rekey output per host, repeat runs, and explicit Git/deployment steps.

Validation: the pinned extension generates real encrypted secrets from the example in both module systems; the test decrypts them, verifies token size and the SSH public/private pair, and confirms a repeat run preserves the ciphertext and public key. A separate flake smoke test exercised the documented generate/rekey app paths, evaluated the resulting age.secrets.api-token.file, and decrypted it with the target host key. All-system evaluation, formatting, and documentation build pass.

Addresses #236 through the extension the issue author already uses. This does not add a second generation engine to core agenix or automatic repository pushes; the issue remains open for a decision on whether core-owned options are still wanted.

AI assistance: example, documentation, and tests prepared with Codex. Human review remains required.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant