add rootfs secrets
This commit is contained in:
20
README.md
20
README.md
@@ -1,14 +1,9 @@
|
||||
Config
|
||||
------
|
||||
|
||||
This is an attempt to configure my NixOS servers with [krops][1]. Usage:
|
||||
Flakes:
|
||||
|
||||
$ direnv allow .
|
||||
$ nix-build ./krops.nix -A hel1a && ./result
|
||||
|
||||
There is probably nothing to look at here.
|
||||
|
||||
Upcoming flakes:
|
||||
$ deploy --interactive '#vno1-oh2'
|
||||
|
||||
$ nix build .#deploy.nodes.hel1-a.profiles.system.path
|
||||
|
||||
@@ -26,14 +21,3 @@ Encode a secret on host:
|
||||
Decode a secret on host (to test things out):
|
||||
|
||||
rage -d -i /etc/ssh/ssh_host_ed25519_key secret.age
|
||||
|
||||
Bootstrapping
|
||||
-------------
|
||||
|
||||
Prereqs:
|
||||
|
||||
mkdir -p /etc/secrets/initrd
|
||||
ssh-keygen -t ed25519 -f /etc/secrets/initrd/ssh_host_ed25519
|
||||
|
||||
[1]: https://cgit.krebsco.de/krops/about/
|
||||
|
||||
|
||||
Reference in New Issue
Block a user