the.bay.news

How bad is manually deploying secrets?

NixOS Discourse
How bad is manually deploying secrets?
I’m planning to use NixOS for a single home server, its services require a handful of secrets, and I’m trying to decide how to manage the secrets. The simplest approach I see is to just specify absolute paths to secrets files in my configuration and then manually/out-of-band deploy those secrets when bringing up the server. Obviously, this relies on external state, isn’t reproducible, etc., but the upside is that it’s just a quick scp and I’m done. How bad of an idea is this? What gotchas do I...

0 comments

Sign in to join the discussion — your thebay.events account works here.

No comments yet.