summary refs log tree commit diff
path: root/os/README.md
diff options
context:
space:
mode:
Diffstat (limited to 'os/README.md')
-rw-r--r--os/README.md17
1 files changed, 12 insertions, 5 deletions
diff --git a/os/README.md b/os/README.md
index 8ca3356..80db948 100644
--- a/os/README.md
+++ b/os/README.md
@@ -1,8 +1,15 @@
-# os configuration
+# OS configuration
 
-TODO script that does:
+use `os-conf` to save and `os-conf -r /` to restore configuration
+the script reads a manifest file inside `$OS_DIR`, which defaults to `$HOME/os`
 
-* parse manifest
-* backup listed files from rootfs
-* patch/add files in rootfs
+## manifest syntax
 
+lines prefixed with `#` or `$` are ignored, the magic comment `#secret`, when
+appended to a line, marks the entry as containing data that shouldn't be checked
+into a public repository. Instead we use [sops](https://github.com/mozilla/sops) to encrypt and store it under
+`$OS_DIR/tmp/os-secret-*`. These encrypted archives are transparently handled
+by the restore code.
+
+Encryption requires the `SOPS_PGP_FP` environment variable (or whatever is required
+by any of the other supported encryption schemes).