-
Notifications
You must be signed in to change notification settings - Fork 19
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Selectively disabling copying generated secrets to host #43
Comments
This is a pretty great idea, I've would have had use for this myself already, but it requires changes to agenix to work properly since agenix installs anything in So our only way to achieve this right now would be to replace the |
Yeah I struggled with that one too - my suggestion above was the best I could come up with in the moment.
Yeah that was my though too.
I'm not sure I get this right, would you be able to provide an example? |
When you define a secret, you set So to have an option |
My idea is to auto-generate and archive unique root passwords per machine using
agenix-rekey
.I was able to setup some generators to get this to work using nicely.
With this setup the unencrypted root password will be stored in
/run/agenix.d/1/user-pw-root
which is not ideal from a security perspective and superfluous since the hash is also available.It would be great to have an option to prevent
user-pw-root
from being copied to the machine, maybe something like:The text was updated successfully, but these errors were encountered: