Skip to content

chore: use KMS-only SOPS encryption#7

Merged
xnoto merged 1 commit into
mainfrom
chore/add-sops-kms-recipient
Jun 19, 2026
Merged

chore: use KMS-only SOPS encryption#7
xnoto merged 1 commit into
mainfrom
chore/add-sops-kms-recipient

Conversation

@xnoto

@xnoto xnoto commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

Summary

  • remove the age recipient from .sops.yaml
  • re-key secrets/secrets.yaml so SOPS metadata is KMS-only

Validation

  • AWS_PROFILE=makeitwork sops decrypt --output /dev/null secrets/secrets.yaml
  • verified SOPS metadata has kms=1 and age=0
  • PCT_TFPATH=$(command -v tofu) pre-commit run --all-files

@xnoto xnoto force-pushed the chore/add-sops-kms-recipient branch from 8ab02b6 to f843f84 Compare June 19, 2026 04:22
@github-actions

Copy link
Copy Markdown

OpenTofu Plan

No changes. Your infrastructure matches the configuration.

OpenTofu has compared your real infrastructure against your configuration and

@xnoto xnoto merged commit 922219a into main Jun 19, 2026
3 checks passed
@xnoto xnoto deleted the chore/add-sops-kms-recipient branch June 19, 2026 04:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant