Rendered at 22:15:11 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
eqvinox 2 days ago [-]
Who other than nixOS has this problem? Feels like a nixOS thing to me, which I'm not going to complicate my applications for. All the orchestration tools have something like a vault, don't they?
Happy to be shown wrong though.
austinshea 16 hours ago [-]
just explain your pattern.
what you are saying means you have a leaky chain of custody and are fine with that,
but you can show why i'm wrong.
burnt-resistor 2 days ago [-]
Use a template-based configuration management system to pull in secrets from a secrets management system (passwords/credentials/PKI management). It's an antipattern to add even more complexity by bolting on configuration or secrets management as part of nix, systemd, or anything else that's OS- or distro-specific. Package managers, and OSes need to offer sane defaults but then have sensible boundaries and allow configuration responsibility to be delegated to users and/or configuration management.
eviks 2 days ago [-]
How would that help if the result of the template is the same single config file that doesn't separate concerns?
Happy to be shown wrong though.
what you are saying means you have a leaky chain of custody and are fine with that,
but you can show why i'm wrong.