Archived
Migrate live secrets to sops-nix (Milestone 2)
Check NixOS configurations / eval-hosts (push) Failing after 11m5s
Check NixOS configurations / eval-hosts (push) Failing after 11m5s
Audited the working tree and full git history for committed secrets
(gitleaks + trufflehog + manual grep, see secrets-inventory.md, kept
local/gitignored per the spec). Found: a password hash shared by root
and the nixos user across every host, two live Beszel monitoring
tokens, and a GitHub fine-grained PAT embedded in a home-manager
nix.conf.
Migrates all of them to sops-nix:
- .sops.yaml + secrets/*.yaml, encrypted for admin + the age keys
derived (via ssh-to-age) from each live host's existing SSH host
key — no new key material transferred to any machine.
- users.users.{root,nixos}.hashedPasswordFile replaces the inline
hashedPassword shared by every target.
- The GitHub PAT moves from a home-manager-managed, store-visible
nix.conf to a sops.templates-rendered file included via nix.conf's
native !include, system-wide instead of per-user.
- Beszel TOKEN moves from `environment` (store-visible) to
`environmentFile` (runtime-only via sops.templates); the dead
commented-out docker token is removed from the tree entirely.
Added a tracked pre-commit hook (gitleaks protect --staged, wired via
core.hooksPath) so a secret can't be committed by accident again, and
documented the sops workflow in README.md.
Structural verification only: all 17 flake targets evaluate, and
`nix build --dry-run --no-link` succeeds for the three currently
deployed hosts. Per CLAUDE.md, actual `nixos-rebuild switch` — the
step that confirms secrets decrypt and services start on a real
machine — is left for manual verification.
Git history still contains the original plaintext secrets; scrubbing
history (Milestone 3) and rotating every credential (Milestone 4) are
separate, deliberately gated steps per remove-sensetive-info-refactor.md.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -86,7 +86,25 @@ review sessions.
|
||||
|
||||
## Security Notes
|
||||
|
||||
Do not commit tokens, private keys, live credentials, or new password hashes.
|
||||
This repository currently contains committed password hashes in shared NixOS
|
||||
configuration; rotate those passwords and move hashes into host-local secret
|
||||
management before treating the repository as public or widely shared.
|
||||
Do not commit tokens, private keys, live credentials, or new password hashes
|
||||
as plaintext. Secrets are managed with [sops-nix](https://github.com/Mic92/sops-nix):
|
||||
encrypted files live under `secrets/`, recipients (per-host age keys derived
|
||||
from each host's existing SSH host key, plus an admin key) are declared in
|
||||
`.sops.yaml`. To add or edit a secret:
|
||||
|
||||
```bash
|
||||
nix-shell -p sops --run "sops secrets/<file>.yaml"
|
||||
```
|
||||
|
||||
then reference it from a module via `config.sops.secrets."<name>".path`
|
||||
(or `sops.templates` for values that need to be embedded in a rendered
|
||||
config file, e.g. `nix.conf`'s `access-tokens`). Never write a secret value
|
||||
directly into a tracked `.nix` file. A pre-commit hook (`.githooks/`,
|
||||
enabled via `git config core.hooksPath .githooks`, done automatically by
|
||||
`scripts/codex-setup.sh`) runs `gitleaks protect --staged` to catch mistakes
|
||||
before they're committed.
|
||||
|
||||
This repository's git *history* still contains secrets committed before this
|
||||
migration (see `remove-sensetive-info-refactor.md`) — those are being
|
||||
scrubbed and rotated separately; don't treat the repo as safe to make public
|
||||
until that's finished.
|
||||
|
||||
Reference in New Issue
Block a user