Skip to content

Commit

Permalink
docs: expand a bit on user secrets + impermanence.
Browse files Browse the repository at this point in the history
See also the discussion at #149
  • Loading branch information
nicdumz authored and Mic92 committed Jan 17, 2025
1 parent 553c7cb commit 4c4fb93
Showing 1 changed file with 12 additions and 3 deletions.
15 changes: 12 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -571,9 +571,18 @@ $y$j9T$WFoiErKnEnMcGq0ruQK4K.$4nJAY3LBeBsZBTYSkdTOejKU6KlDmhnfUV3Ll1K/1b.
}
```

**Note:** If you are using Impermanence, you must set `sops.age.keyFile` to a keyfile inside your persist directory or it will not exist at boot time.
For example: `/nix/persist/var/lib/sops-nix/key.txt`
Similarly if ssh host keys are used instead, they also need to be placed inside the persisted storage.
**Note:** If you are using Impermanence, the key used for secret decryption (`sops.age.keyFile`, or the host SSH keys) must be in a persisted directory,
loaded early enough during boot. For example:

```nix
sops.age.keyFile = "/nix/persist/var/lib/sops-nix/key.txt";
```

or:

```nix
fileSystems."/etc/ssh".neededForBoot = true;
```

## Different file formats

Expand Down

0 comments on commit 4c4fb93

Please sign in to comment.