Jump to
↵select↑↓navigateescclose

Reference

Secrets options

Every frappe-nix.secrets option, declared at the top level of the flake, with types and defaults.

Updated
Tags
  • options
  • reference
  • secrets
  • age
On this page

These options sit at the flake's top level, not under perSystem. Recipients and .age paths are facts about the bench rather than about a platform, and agenix-shell's own secret options are top-level for the same reason. The types and defaults were checked against the module by evaluating it. For the concepts, see Secrets.

OptionTypeDefaultNotes
enableboolrecipients != { }Wire agenix and agenix-shell into this bench.
dirpathrequiredWhere the .age files live, such as ./secrets. Write it as a path literal relative to your flake.nix.
relDirstrbaseNameOf dirThe same directory relative to the bench root. Override only if dir is nested, for example dir = ./nix/secrets; needs relDir = "nix/secrets";.
recipientsattrs of SSH public key{ }The people who may decrypt. The attribute names become labels in error messages. After changing it, run rekey-secrets.
hostRecipientsattrs of SSH public key{ }Deployment host keys. Added to the per-site secrets, and to others only where hosts = true.
identityPathslist of str[ "$HOME/.ssh/id_ed25519" "$HOME/.ssh/id_rsa" ]Private keys tried when decrypting, in order. Shell strings, expanded at runtime, which is why the dev shell needs --no-pure-eval.
backupAccess.enableboolsecrets.enableDeclare <dir>/backup-access.age: the object-store credentials for fetching production backups, as an env-file.
backupAccess.hostsboolfalseAlso encrypt backup-access.age to hostRecipients.
sites.<NAME>.encryptionKeybooltrueDeclare <dir>/<NAME>/encryption-key.age: the Frappe encryption key, one line. Also what encryptionKeyFile wants in production.
sites.<NAME>.databasePasswordbooltrueDeclare <dir>/<NAME>/db-password.age, one line. The counterpart of database.passwordFile.
sites.<NAME>.extraConfigbooltrueDeclare <dir>/<NAME>/site-config.age, a JSON object deep-merged into site_config.json. The counterpart of extraConfigFiles.
sites.<NAME>.developersbooltrueLet recipients read this site's secrets, not just hostRecipients. false is a useful tier: someone who can fetch and restore the database but cannot read the credentials stored inside it.
extra.<NAME>.formatenv, raw or json"env"How the dev shell consumes the plaintext. env is KEY=value lines, sourced by the shell. raw is a single value, $<var>. json is a JSON object left on disk, with $<var>_PATH pointing at it.
extra.<NAME>.varstr"frappe_<NAME>"The shell variable name.
extra.<NAME>.hostsboolfalseAlso encrypt this secret to hostRecipients.

backup-access.age

The env-file bench restore reads has these keys:

BACKUPS_URL=https://s3.us-east-005.backblazeb2.com
BACKUPS_ACCESS_KEY=<ACCESS_KEY>
BACKUPS_SECRET_KEY=<SECRET_KEY>
BACKUPS_BUCKET=<BUCKET_NAME>
BACKUPS_PREFIX=Backups/      # optional

The bucket and prefix live in the secret rather than in Nix on purpose. They are per-deployment facts that change together with the credentials, and keeping them together means bench restore needs no Nix configuration at all.

Read-only output

When secrets are enabled, the flake also exposes lib.frappeSecrets with recipients, sites and files, so a deployment can read the same ciphertext. See Use the same secrets on the server.