Add a SOPS recipient¶
Every secret file is encrypted to a list of age recipients, and only those can decrypt it. Add a recipient when a second host deploys the same secrets, or when another admin needs to edit them.
Get the recipient's public key¶
For a host, convert its public SSH host key:
| Bash | |
|---|---|
For an admin, they print it from their own key file:
| Bash | |
|---|---|
Add it to .sops.yaml¶
Add the key and list it in every creation rule whose files it should decrypt:
| .sops.yaml | |
|---|---|
New files pick up the rule when you create them. To give each host only its own secrets, use one rule per host directory instead (see Manage several hosts).
Re-encrypt the existing files¶
| Bash | |
|---|---|
This changes the files, although the values stay the same. syslet sees new ciphertext, so the next apply on each host that uses the files updates their podman secrets and restarts every container that references them. Commit and apply when a restart suits you.
Related tasks¶
Remove a recipient¶
Delete the key from .sops.yaml and run sops updatekeys again.
The removed key can still decrypt every older version of the files in git history, so change the values too (see Rotate a secret).