Supersede ADR 0001's SSH-derived key mechanism with an admin identity held
outside the repo plus a per-host identity on each encrypted root. Decoupling
the two is what lets the SSH host keys become secrets themselves rather than
the root of trust they were.
Add the spec, the three implementing tasks, and the glossary terms the
breakdown speaks in.
Capture the design work for the NixOS migration before any implementation:
- .claude/CONTEXT.md: domain glossary (Host, Module, Skeleton, Auto-loader,
Enable convention, unstable/stable overlay)
- .claude/adr/0001-sops-nix-for-secrets.md: secrets tooling decision
- .claude/spec/laptop-mvi.md: frozen minimum-viable-install spec for neogaia
- reference/: read-only snapshot of the current CachyOS configs (secrets and
state excluded), plus ENVIRONMENT.md profiling the live environment to guide
replication