Skip to content
ryantmPublic

About

age-encrypted secrets for NixOS and Home manager

Topics

Resources

Security policy

Stars

2.5k stars

Watchers

14 watching

Forks

Latest commit

 

History

385 Commits

Folders and files

Repository files navigation

agenix: age-encrypted secrets for NixOS and Home Manager

Read the documentation.

agenix encrypts secrets with SSH public keys so the encrypted files can be stored and deployed with Nix. Its CLI creates and rekeys .age files; the NixOS and Home Manager modules decrypt them at activation time for the intended machine or user.

Quick start

Add the NixOS module to your flake:

{
  inputs.nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
  inputs.agenix.url = "github:ryantm/agenix";

  outputs = { nixpkgs, agenix, ... }: {
    nixosConfigurations.my-host = nixpkgs.lib.nixosSystem {
      system = "x86_64-linux";
      modules = [ agenix.nixosModules.default ./configuration.nix ];
    };
  };
}

In a secrets directory, create agenix-rules.nix listing the public SSH keys allowed to decrypt each file. Then run nix run github:ryantm/agenix -- -e example.age to create an encrypted secret. Declare it in a NixOS module:

{
  age.secrets.example.file = ./secrets/example.age;
  # Use config.age.secrets.example.path wherever a service expects a secret file.
}

The tutorial shows a complete rules file, key discovery, installation, and deployment.

Documentation

For help, use GitHub issues.

About

age-encrypted secrets for NixOS and Home manager

Topics

Resources

Security policy

Stars

2.5k stars

Watchers

14 watching

Forks

Releases

Packages

Used by

Contributors

Languages