feat(docs): describe evaluation time secrets

This commit is contained in:
Sk7Str1p3 2026-05-03 00:48:46 +03:00
parent cc351c88c0
commit 3c03464b24
No known key found for this signature in database
GPG key ID: 4DD995933D06D43B
2 changed files with 10 additions and 0 deletions

View file

@ -96,6 +96,7 @@ stdenvNoCC.mkDerivation {
[Introduction](README.md) [Introduction](README.md)
- [Features]() - [Features]()
- [Evaluation time secrets](evalSecrets.md)
- [Documentation generation](docGen.md) - [Documentation generation](docGen.md)
'' ''

9
docs/src/evalSecrets.md Normal file
View file

@ -0,0 +1,9 @@
# Evaluation time secrets
Some secrets cannot be left in cleartext (e.g time zone, user's real names), but are required at evaluation time,
and in some cases using sops-nix's template is really inconvenient.
To handle this, __currently__ i use strange approach: I manually encrypt files with sops, commit them and manually decrypt.
[git-agecrypt](https://github.com/vlaci/git-agecrypt) wasn't suitable for me.
In future, i will replace it with my own implementation of transparent git encryption based on sops.
Also, this used only for secrets which may be safely left in world-readable store. For more sensitive secrets I use `sops-nix`, which decrypts secrets only at runtime.