Archived
fix(sync-host-keys): extend --remove/--regenerate to cover clan vars
Check NixOS configurations / eval-hosts (pull_request) Successful in 10m26s
Check NixOS configurations / eval-hosts (pull_request) Successful in 10m26s
locally_managed_hosts() only scanned host-keys/ (now empty for all current targets), so --remove and --regenerate-all-keys silently did nothing. Fix: - locally_managed_hosts(): also yields targets from vars/per-machine/*/openssh/ssh_host_ed25519_key/secret, deduped - cmd_remove: shows [clan-vars] or [host-keys/] label per entry; deletes vars/per-machine/<target>/openssh/ in addition to host-keys/ - cmd_regenerate_all: same -- removes clan vars dirs before regenerating Also update CLAUDE.md and README.md to reflect that all flake targets now use clan vars (not just lxc-*); host-keys/ is only for the auto-installer's own pre-seeding path. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01B2EJ4qTsM5KUqhS5c3GAwx
This commit is contained in:
@@ -27,12 +27,13 @@ machines when deployed.
|
||||
template for a *real* host — every other host uses sops-nix
|
||||
(`hashedPasswordFile`, see "Security Notes" in `README.md`). Flag any *new*
|
||||
secret-like string you encounter instead of committing it.
|
||||
- `host-keys/` is gitignored — locally-generated *private* SSH host keys
|
||||
for the auto-installer and non-LXC hosts (see `docs/auto-installer.md`).
|
||||
Never commit its contents; if `git status` ever shows it as trackable,
|
||||
something is wrong. Deployed LXC hosts use clan vars
|
||||
(`vars/per-machine/<target>/openssh/`, committed and sops-encrypted)
|
||||
instead — those ARE tracked by git and belong in the repo.
|
||||
- `host-keys/` is gitignored — used only by the auto-installer's own
|
||||
environment for pre-seeding non-LXC host keys before first boot (see
|
||||
`docs/auto-installer.md`). Never commit its contents; if `git status`
|
||||
ever shows it as trackable, something is wrong. All deployed hosts use
|
||||
clan vars (`vars/per-machine/<target>/openssh/`, committed and
|
||||
sops-encrypted) for their SSH host keys — those ARE tracked by git and
|
||||
belong in the repo.
|
||||
|
||||
### Two Proxmox nodes: `pve1.sweet.home` (production) and `pve-test.sweet.home` (sandbox)
|
||||
|
||||
@@ -206,11 +207,11 @@ instead of copying it.
|
||||
- `scripts/secrets/sync-host-keys.sh` — generates/registers SSH host keys
|
||||
and their `.sops.yaml`/`secrets/*.yaml` recipients for flake targets,
|
||||
idempotently (`--all`, `<target>`, `--remove`, `--regenerate-all-keys`,
|
||||
all with `--dry-run`). For lxc-* targets it stores keys as clan vars
|
||||
(`vars/per-machine/<target>/openssh/`, committed and sops-encrypted);
|
||||
for other targets it uses the gitignored `host-keys/` directory. The
|
||||
primary tool for provisioning a new host's secrets access — see
|
||||
"Creating a new machine" in `docs/auto-installer.md`.
|
||||
all with `--dry-run`). Stores keys as clan vars
|
||||
(`vars/per-machine/<target>/openssh/`, committed and sops-encrypted) for
|
||||
all flake targets. The primary tool for provisioning a new host's
|
||||
secrets access — see "Creating a new machine" in
|
||||
`docs/auto-installer.md`.
|
||||
- `scripts/secrets/prepare-host-key.sh` — narrower predecessor: generates a
|
||||
key by an arbitrary name without touching `.sops.yaml`. Still useful to
|
||||
pre-generate a key before its flake target exists yet, since
|
||||
|
||||
Reference in New Issue
Block a user