# Recipients for the encrypted files under secrets/. keys: # On every file: one whose only recipients are machines becomes unrecoverable # the moment they are wiped, and adding a recipient requires decrypting first. # The private half is held outside this repo, in the operator's password manager. - &admin age1m0pk94ysjlw3lmf6pyuv5l5pepvdjss8w0vxjv90dq6ndp02tdgsdwdvue # Generated on the machine it names, and reads only that machine's secrets # plus the shared file. - &neogaia age14a04vphzjq74epfrz9a09wjw8lzchtru84awzuq2n45d8f42ychqjs89qe creation_rules: # Material common to every machine, so it is stored once rather than per host. - path_regex: secrets/shared\.yaml$ key_groups: - age: - *admin - *neogaia