Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check command #297

Open
jalil-salame opened this issue Oct 31, 2024 · 0 comments
Open

Check command #297

jalil-salame opened this issue Oct 31, 2024 · 0 comments

Comments

@jalil-salame
Copy link

I'd like an agenix --check command for CI, to ensure fetched keys (e.g. https://github.com/jalil-salame.keys) are not out of date in the recipient files.

Running agenix --rekey in CI is not an option:

  1. I don't want CI to have access to the secrets
  2. agenix --rekey changes all files even if unnecessary.
    This is because age uses a nonce which is generated when you call encrypt, calling --rekey regenerates this nonce and causes all the data to change.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant