Archived
fix(ipa): use in-place sops encryption in module docs
sops matches creation rules against the input file path, so encrypting /tmp/<host>.keytab directly with stdout redirect fails to find the rule. Copy to secrets/ first, then use -i to encrypt in-place. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -20,9 +20,11 @@
|
||||
# ipa host-add <fqdn> --ip-address=<ip>
|
||||
# ipa-getkeytab -s <ipa-server> -p host/<fqdn> -k /tmp/<host>.keytab
|
||||
#
|
||||
# 3. sops-encrypt the keytab as a binary secret from your admin machine:
|
||||
# sops -e --input-type binary /tmp/<host>.keytab \
|
||||
# > secrets/<host>.keytab
|
||||
# 3. sops-encrypt the keytab as a binary secret from your admin machine
|
||||
# (must run from repo root; sops matches creation rules against the file
|
||||
# path, so copy to secrets/ first and encrypt in-place):
|
||||
# cp /tmp/<host>.keytab secrets/<host>.keytab
|
||||
# sops -e --input-type binary -i secrets/<host>.keytab
|
||||
# Add secrets/<host>.keytab to .sops.yaml with the host's age key as a
|
||||
# recipient (see the nix-cache.keytab entry for the pattern), then run:
|
||||
# scripts/secrets/sync-host-keys.sh <target> # if not done yet
|
||||
|
||||
Reference in New Issue
Block a user