- modules/desktop-age-secrets.nix: agenix + rage wrapped with age-plugin-tpm, TPM identity primary, admin SSH key fallback for recovery/pre-bootstrap - modules/desktop-lanzaboote-agenix.nix: extract secureboot.tar at activation - modules/desktop-networkmanager.nix: revert to simple import of git-crypt file - modules/server-age-secrets.nix: renamed from age-secrets.nix - modules/desktop-common.nix: wire netrc + password-hash to agenix paths - hosts/yarn/impermanence.nix: persist /var/lib/agenix across tmpfs wipes - secrets/secrets.nix: recipient declarations (admin + tpm + muffin USB) - secrets/desktop/*.age: secureboot.tar, nix-cache-netrc, password-hash - scripts/bootstrap-desktop-tpm.sh: generate TPM identity + print recipient
30 KiB
30 KiB