[#5] adding sops support

This commit is contained in:
Dennis Frieberg 2023-09-25 21:03:23 +02:00
parent 22552bd095
commit cf537f3c7b
Signed by: nerf
GPG key ID: 1EC6F5573876CC80
6 changed files with 89 additions and 2 deletions

16
.sops.yaml Normal file
View file

@ -0,0 +1,16 @@
keys:
- &nerf age1rasjnr2tlv9y70sj0z0hwpgpxdc974wzg5umtx2pnc6z0p05u3js6r8sln
- &nyarlathotep age1s99d0vlj5qlm287n98jratql5fypvjrxxal0k5jl2aw9dcc8kyvqw5yyt4
creation_rules:
- path_regex nixos/machines/nyarlathotep/.*
key_groups:
- age:
*nerf
*nyarlathotep
# this is the catchall clause if nothing above machtes. Encrypt to users but not
# to machines
- key_groups:
- age:
*nerf