diff options
Diffstat (limited to 'os/README.md')
| -rw-r--r-- | os/README.md | 17 |
1 files changed, 12 insertions, 5 deletions
diff --git a/os/README.md b/os/README.md index 8ca3356..80db948 100644 --- a/os/README.md +++ b/os/README.md @@ -1,8 +1,15 @@ -# os configuration +# OS configuration -TODO script that does: +use `os-conf` to save and `os-conf -r /` to restore configuration +the script reads a manifest file inside `$OS_DIR`, which defaults to `$HOME/os` -* parse manifest -* backup listed files from rootfs -* patch/add files in rootfs +## manifest syntax +lines prefixed with `#` or `$` are ignored, the magic comment `#secret`, when +appended to a line, marks the entry as containing data that shouldn't be checked +into a public repository. Instead we use [sops](https://github.com/mozilla/sops) to encrypt and store it under +`$OS_DIR/tmp/os-secret-*`. These encrypted archives are transparently handled +by the restore code. + +Encryption requires the `SOPS_PGP_FP` environment variable (or whatever is required +by any of the other supported encryption schemes). |