# Recipients for the encrypted files under secrets/. keys: # A recipient of every file: # one readable only by machines is unrecoverable once they are wiped, # and adding a recipient requires decrypting first. # No private half here; it is held only in the operator's password manager. - &admin age1m0pk94ysjlw3lmf6pyuv5l5pepvdjss8w0vxjv90dq6ndp02tdgsdwdvue # Generated on the machine it names. - &neogaia age14a04vphzjq74epfrz9a09wjw8lzchtru84awzuq2n45d8f42ychqjs89qe creation_rules: # Material common to every machine, so it is stored once rather than per host. - path_regex: secrets/shared\.yaml$ key_groups: - age: - *admin - *neogaia