fix: dont redecrypt secrets every time
This commit is contained in:
parent
39a50168c9
commit
3c7b5ac006
|
@ -31,6 +31,10 @@ in {
|
||||||
"/var/log"
|
"/var/log"
|
||||||
"/var/lib/systemd"
|
"/var/lib/systemd"
|
||||||
"/var/lib/nixos"
|
"/var/lib/nixos"
|
||||||
|
{
|
||||||
|
directory = "/var/tmp/nix-import-encrypted/";
|
||||||
|
mode = "0777";
|
||||||
|
}
|
||||||
{
|
{
|
||||||
directory = "/var/tmp/agenix-rekey";
|
directory = "/var/tmp/agenix-rekey";
|
||||||
mode = "0777";
|
mode = "0777";
|
||||||
|
|
|
@ -23,7 +23,7 @@ new_name="$(sha512sum "$file")"
|
||||||
new_name="${new_name:0:32}-${basename//"/"/"%"}"
|
new_name="${new_name:0:32}-${basename//"/"/"%"}"
|
||||||
|
|
||||||
# Derive the path where the decrypted file will be stored
|
# Derive the path where the decrypted file will be stored
|
||||||
out="/tmp/nix-import-encrypted/$new_name"
|
out="/var/tmp/nix-import-encrypted/$new_name"
|
||||||
mkdir -p "$(dirname "$out")"
|
mkdir -p "$(dirname "$out")"
|
||||||
|
|
||||||
# Decrypt only if necessary
|
# Decrypt only if necessary
|
||||||
|
|
Loading…
Reference in a new issue