infra/.sops.yaml

79 lines
1.8 KiB
YAML
Raw Normal View History

2021-09-25 22:35:51 +02:00
keys:
- &zimbatm 260353B993F8CE16752EF48C71BAF6D40C1D63D7
2021-09-25 22:35:51 +02:00
- &mic92 age17n64ahe3wesh8l8lj0zylf4nljdmqn28hvqns2g7hgm9mdkhlsvsjuvkxz
2021-09-26 16:13:37 -07:00
- &ryantm age1d87z3zqlv6ullnzyng8l722xzxwqr677csacf3zf3l28dau7avfs6pc7ay
2021-09-25 22:35:51 +02:00
- &build01 age17jtyn2y4fpey6q7ers9gtnh4580xj89zdjuew9nqhxywmsaw94fs5udupc
2021-10-24 01:02:16 +02:00
- &build02 age1kh6yvgxz9ys74as7aufdy8je7gmqjtguhnjuxvj79qdjswk2r3xqxf2n6d
2021-09-25 22:35:51 +02:00
- &build03 age1qg7tfjwzp6dxwkw9vej6knkhdvqre3fu7ryzsdk5ggvtdx854ycqevlwnq
- &build04 age1vr4suv4lhtt8f59s25eukdfk67j7av72gvj7sk7ux6thusct3utqmn3pmf
# scan new hosts like this:
# $ nix-shell -p ssh-to-age --run 'ssh-keyscan buildXX.nix-community.org | ssh-to-age'
creation_rules:
- path_regex: secrets.yaml$
key_groups:
- age:
- *mic92
- *ryantm
pgp:
- *zimbatm
- path_regex: terraform/secrets.yaml$
key_groups:
- age:
- *mic92
- *ryantm
pgp:
- *zimbatm
2021-09-25 22:35:51 +02:00
- path_regex: build01/[^/]+\.yaml$
key_groups:
- age:
- *mic92
2021-09-26 16:13:37 -07:00
- *ryantm
2021-09-25 22:35:51 +02:00
- *build01
pgp:
- *zimbatm
2021-09-25 22:35:51 +02:00
- path_regex: build02/[^/]+\.yaml$
key_groups:
- age:
- *mic92
2021-09-26 16:13:37 -07:00
- *ryantm
2021-09-25 22:35:51 +02:00
- *build02
pgp:
- *zimbatm
2021-09-25 22:35:51 +02:00
- path_regex: build03/[^/]+\.yaml$
key_groups:
- age:
- *mic92
2021-09-26 16:13:37 -07:00
- *ryantm
2021-09-25 22:35:51 +02:00
- *build03
pgp:
- *zimbatm
2021-09-25 22:35:51 +02:00
- path_regex: build04/[^/]+\.yaml$
key_groups:
- age:
- *mic92
2021-09-26 16:13:37 -07:00
- *ryantm
2021-09-25 22:35:51 +02:00
- *build04
pgp:
- *zimbatm
- path_regex: roles/hercules-ci/.+\.yaml$
key_groups:
- age:
- *mic92
- *ryantm
2021-12-26 08:58:06 +01:00
- *build02
- *build03
- *build04
pgp:
- *zimbatm
2021-12-23 20:39:49 +01:00
- path_regex: roles/.+\.yaml$
2021-09-25 22:35:51 +02:00
key_groups:
- age:
- *mic92
2021-09-26 16:13:37 -07:00
- *ryantm
2021-09-25 22:35:51 +02:00
- *build01
- *build02
- *build03
- *build04
pgp:
- *zimbatm