Implement sops/agenix for secrets in repo; plan Vault for future #56

Open
opened 2025-09-01 14:25:53 +00:00 by chris · 0 comments
Owner

Description

  • Integrate sops or agenix into the flake and repositories so secrets are encrypted in Git.
  • Document plan and timeline to move to HashiCorp Vault or similar for dynamic secrets later.

Priority: P1
Estimate: 6 hours
Acceptance criteria

  • No plaintext secrets in repo.
  • Deploy process can decrypt secrets during build/deploy on authorized hosts.
Description - Integrate sops or agenix into the flake and repositories so secrets are encrypted in Git. - Document plan and timeline to move to HashiCorp Vault or similar for dynamic secrets later. Priority: P1 Estimate: 6 hours Acceptance criteria - No plaintext secrets in repo. - Deploy process can decrypt secrets during build/deploy on authorized hosts.
chris added this to the E - Hardening, Backups & DR milestone 2025-09-01 14:25:53 +00:00
chris added the
secrets
security
infra
labels 2025-09-01 14:25:53 +00:00
chris self-assigned this 2025-09-01 14:25:53 +00:00
chris added this to the MVP project 2025-09-03 06:51:58 +00:00
This repository is archived. You cannot comment on issues.
No description provided.