2 Encrypted secrets
Steffo edited this page 2026-08-27 15:45:51 +02:00

Encrypted secrets

Secrets are stored in-repo, and are encrypted using SOPS, so that they can be included in pull requests.

The public key to encrypt new secrets is included and configured in .sops.yaml 123, so it can be used without any setup.

To keep collaboration simple, we share a single private key among all collaborators and the cluster.
Ask another collaborator to send it to you via a secure channel, and place it in $XDG_CONFIG_HOME/sops/age/keys.txt 4.

Usage

To encrypt a secret, run:

.scripts/secret-encrypt.bash .my-secret.Secret.yaml

To decrypt a secret, run:

.scripts/secret-decrypt.bash .my-secret.Encrypted.yaml