fix: dont redecrypt secrets every time

This commit is contained in:
Patrick 2024-04-12 12:19:47 +02:00
parent 39a50168c9
commit 3c7b5ac006
Signed by: patrick
GPG key ID: 451F95EFB8BECD0F
2 changed files with 5 additions and 1 deletions

View file

@ -31,6 +31,10 @@ in {
"/var/log"
"/var/lib/systemd"
"/var/lib/nixos"
{
directory = "/var/tmp/nix-import-encrypted/";
mode = "0777";
}
{
directory = "/var/tmp/agenix-rekey";
mode = "0777";

View file

@ -23,7 +23,7 @@ new_name="$(sha512sum "$file")"
new_name="${new_name:0:32}-${basename//"/"/"%"}"
# Derive the path where the decrypted file will be stored
out="/tmp/nix-import-encrypted/$new_name"
out="/var/tmp/nix-import-encrypted/$new_name"
mkdir -p "$(dirname "$out")"
# Decrypt only if necessary