From dd31339e49c28b9c719b60425c5f7ae31a0e45f4 Mon Sep 17 00:00:00 2001 From: Robert Günzler Date: Fri, 1 Jul 2022 16:50:25 +0200 Subject: os: finish implementing including encryption using sops --- os/README.md | 17 ++++++++++++----- 1 file changed, 12 insertions(+), 5 deletions(-) (limited to 'os/README.md') diff --git a/os/README.md b/os/README.md index 8ca3356..80db948 100644 --- a/os/README.md +++ b/os/README.md @@ -1,8 +1,15 @@ -# os configuration +# OS configuration -TODO script that does: +use `os-conf` to save and `os-conf -r /` to restore configuration +the script reads a manifest file inside `$OS_DIR`, which defaults to `$HOME/os` -* parse manifest -* backup listed files from rootfs -* patch/add files in rootfs +## manifest syntax +lines prefixed with `#` or `$` are ignored, the magic comment `#secret`, when +appended to a line, marks the entry as containing data that shouldn't be checked +into a public repository. Instead we use [sops](https://github.com/mozilla/sops) to encrypt and store it under +`$OS_DIR/tmp/os-secret-*`. These encrypted archives are transparently handled +by the restore code. + +Encryption requires the `SOPS_PGP_FP` environment variable (or whatever is required +by any of the other supported encryption schemes). -- cgit 1.4.1