Archived
Check NixOS configurations / eval-hosts (pull_request) Successful in 11m2s
- Add hosts/tor-relay/host.nix import of host-token.nix so the agent gets its TOKEN from a sops-managed environment file - Add secrets/tor-relay.yaml (encrypted beszel token for this host) - Add creation_rules entry for secrets/tor-relay.yaml in .sops.yaml - Update &lxc-tor-relay age key to the host's actual current key (old key was from a prior LXC incarnation; new key extracted from Switch-nix output: age1gl5ujmhd2pe37...) - Re-encrypt secrets/common.yaml via sops updatekeys to swap in the new key, so the host can decrypt its password hash on next boot Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>