chore(sops): Linus Johansen decrypts the infra vault and the cluster files; the README explains both SOPS setups #15

Merged
Eskpil merged 2 commits from second-operator into main 2026-09-20 16:39:29 +00:00
Owner

Two commits. First: his YubiKey joins the vault config agePublicKey and the vault rule in .sops.yaml, and the vault is re-encrypted through the vault itself (a put rewrites it to every recipient; recipients/reencrypt is that write, kept because the provider cannot delete). Second: his key joins the cluster-file rule and both artifacts/zot/*.enc.yaml are re-encrypted with sops updatekeys, three recipients each; the README Secrets section now explains the two SOPS setups, who decrypts each, their recipients, and how an operator is added or removed.

Two commits. First: his YubiKey joins the vault config agePublicKey and the vault rule in .sops.yaml, and the vault is re-encrypted through the vault itself (a put rewrites it to every recipient; recipients/reencrypt is that write, kept because the provider cannot delete). Second: his key joins the cluster-file rule and both artifacts/zot/*.enc.yaml are re-encrypted with sops updatekeys, three recipients each; the README Secrets section now explains the two SOPS setups, who decrypts each, their recipients, and how an operator is added or removed.
age1yubikey1qwtamp... joins the vault's agePublicKey list and the
matching rule in .sops.yaml; the file is re-encrypted through the vault
itself (a put rewrites it to every recipient), which is what the
recipients/reencrypt key records, since the provider cannot delete it.
The cluster files under apps/ and artifacts/ are unchanged.
beddari force-pushed second-operator from 1aa6091ca5 to 445b6fce52 2026-09-20 16:22:44 +00:00 Compare
beddari changed title from chore(vault): a second human operator's YubiKey decrypts the infra vault to chore(sops): Linus Johansen decrypts the infra vault and the cluster files; the README explains both SOPS setups 2026-09-20 16:27:01 +00:00
His YubiKey joins the first rule in .sops.yaml and both *.enc.yaml under
artifacts/zot are re-encrypted with sops updatekeys, so he can edit and
re-encrypt cluster secrets as well as read the vault. The README's
Secrets section now sets the two setups side by side: cluster files,
decrypted by Flux with the cluster key, recipients the cluster key and
the operators' YubiKeys; the swamp vault, decrypted by the models, its
recipient list in the vault type's own config with the soft key of the
factory host, mirrored by the second sops rule for terminal use; and
what adding or removing an operator takes.
Eskpil merged commit ae0a29d2e9 into main 2026-09-20 16:39:29 +00:00
Eskpil deleted branch second-operator 2026-09-20 16:39:29 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dataverket/fabrikk-infra!15
No description provided.