Use a dedicated decryption key¶
By default, syslet derives its age key from the host's SSH key at /etc/ssh/ssh_host_ed25519_key.
A dedicated key decouples secrets from the host key: you can rotate the host key freely, and restore the dedicated key from a backup after reinstalling the host.
Create the key on the host¶
syslet needs an ed25519 key without a passphrase:
| Bash | |
|---|---|
Back up /etc/syslet/age_ed25519; anyone with it can decrypt the host's secrets.
Point syslet at it¶
Create /etc/syslet/syslet.json on the host:
Run a plan once (cue cmd plan or syslet --diff).
syslet derives the new age key and appends it to /var/lib/syslet/key.txt, which still holds the key derived from the host key, so existing secrets keep decrypting.
If the file at sshKeyPath doesn't exist, syslet exits before planning:
| Text Only | |
|---|---|
Re-encrypt for the new key¶
Convert the public key:
| Bash | |
|---|---|
Replace the host's key in .sops.yaml with it, then re-encrypt and apply:
The new ciphertext updates the podman secrets and restarts every container that references them. Afterwards, drop the host-derived key from the cache as in Rotate the SSH host key.
Related tasks¶
Restore after a reinstall¶
Copy the backed-up key to /etc/syslet/age_ed25519 with mode 0600, and create syslet.json again.
The next apply decrypts the secrets without re-encrypting anything.