per-host age keys, scoped sops files #95
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "audit-pt2"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
nixbldKeyremoved fromsops/privkeys.yaml- burned during the pt1 deploy, was left in sops pending first successful switch; deleted and re-encrypted outsingle shared fleet age key replaced with per-host keys - a compromised host previously held the key to every secret on every other host
.sops.yamlrewritten:creation_rulesnow scope each file to only the hosts that actually consume secrets from itdomain.yaml,mail.yaml->athenaonlyborg.yaml->athena,ishtar,minerva(brigid has no backup job)pki.yaml->ishtar,minerva,brigid(athena uses the BIOS, no lanzaboote)services.yaml->minerva,brigidprivkeys.yaml,pass.yaml-> all four (every host has ssh/wg keys andlamentKey)sops updatekeysto the new per-host pubkeys + personal admin key/persist/key.ageon each host (replaces the shared key in place;sops.age.keyFileconfig unchanged)ceremony/03-gen-host-age-keys.sh,ceremony/04-update-sops-age-keys.sh,ceremony/05-distribute-host-age-keys.shwalk the full rotationleft for later: splitting
privkeys.yamlper-host (would tighten blast radius further but requires touchingsshd.nix+networking.nix); second WG hub onminervaif a public port materializeseec2d11a88ad31f44864ad31f448646e5b1f9602