agenix encrypts secrets with SSH public keys so the encrypted files can be
stored and deployed with Nix. Its CLI creates and rekeys .age files; the
NixOS and Home Manager modules decrypt them at activation time for the
intended machine or user.
Add the NixOS module to your flake:
{
inputs.nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
inputs.agenix.url = "github:ryantm/agenix";
outputs = { nixpkgs, agenix, ... }: {
nixosConfigurations.my-host = nixpkgs.lib.nixosSystem {
system = "x86_64-linux";
modules = [ agenix.nixosModules.default ./configuration.nix ];
};
};
}In a secrets directory, create agenix-rules.nix listing the public SSH keys
allowed to decrypt each file. Then run
nix run github:ryantm/agenix -- -e example.age to create an encrypted
secret. Declare it in a NixOS module:
{
age.secrets.example.file = ./secrets/example.age;
# Use config.age.secrets.example.path wherever a service expects a secret file.
}The tutorial shows a complete rules file, key discovery, installation, and deployment.
- Installation by flakes, niv, nix-channel, or fetchTarball, including Home Manager installation.
- NixOS module reference, Home Manager module reference, and CLI reference.
- Threat model and warnings and contributing and tests.
For help, use GitHub issues.