13e5a9bb5663410c874f5f866940f133825eac13
The closing section still described key derivation from each machine's SSH host key, a mechanism that was superseded because it forces new host keys on every reimage and makes storing those keys as secrets circular. Record the two-tier identity model that replaced it, and warn that the hand-set bootstrap password stops working once the password becomes a secret: hashedPasswordFile outranks every other password option, so a machine installed after that must have its identity provisioned before first boot rather than a password set afterwards.
Description
My NixOS configuration(s)
Languages
Nix
50.5%
TypeScript
48%
Shell
1.2%
Lua
0.3%