chore(sops): Linus Johansen decrypts the infra vault and the cluster files; the README explains both SOPS setups #15
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "second-operator"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Two commits. First: his YubiKey joins the vault config agePublicKey and the vault rule in .sops.yaml, and the vault is re-encrypted through the vault itself (a put rewrites it to every recipient; recipients/reencrypt is that write, kept because the provider cannot delete). Second: his key joins the cluster-file rule and both artifacts/zot/*.enc.yaml are re-encrypted with sops updatekeys, three recipients each; the README Secrets section now explains the two SOPS setups, who decrypts each, their recipients, and how an operator is added or removed.
1aa6091ca5to445b6fce52chore(vault): a second human operator's YubiKey decrypts the infra vaultto chore(sops): Linus Johansen decrypts the infra vault and the cluster files; the README explains both SOPS setups