Skip to content

ci: stop passing SOPS age workflow secret#8

Merged
xnoto merged 1 commit into
mainfrom
ci/remove-sops-age-workflow-secret
Jun 19, 2026
Merged

ci: stop passing SOPS age workflow secret#8
xnoto merged 1 commit into
mainfrom
ci/remove-sops-age-workflow-secret

Conversation

@xnoto

@xnoto xnoto commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

Summary

  • stop passing SOPS_AGE_KEY to the shared OpenTofu workflow
  • rely on AWS KMS via GitHub OIDC for SOPS decryption

Validation

  • AWS_PROFILE=makeitwork sops decrypt --output /dev/null secrets/secrets.yaml
  • PCT_TFPATH=$(command -v tofu) pre-commit run --all-files
  • verified no remaining SOPS_AGE_KEY references in this repo

@github-actions

Copy link
Copy Markdown

OpenTofu Plan

No changes. Your infrastructure matches the configuration.

OpenTofu has compared your real infrastructure against your configuration and

@xnoto xnoto merged commit 94fdad5 into main Jun 19, 2026
3 checks passed
@xnoto xnoto deleted the ci/remove-sops-age-workflow-secret branch June 19, 2026 04:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant