with one click
secrets-management
Managing ragenix-encrypted secrets in the AMC monorepo
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Menu
Managing ragenix-encrypted secrets in the AMC monorepo
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Based on SOC occupation classification
Building, packaging, and deploying MTDediMod releases (server and client mods)
Debugging crash dumps, PDB symbols, and UE4SS Lua GC issues in MTDediMod
SSH access to AMC servers and debugging amc-backend services
| name | secrets-management |
| description | Managing ragenix-encrypted secrets in the AMC monorepo |
Secrets are stored as ragenix-encrypted .age files in the secrets/ directory. Plaintext .env files exist alongside their .age counterparts for editing convenience.
| Plaintext | Encrypted | Used by |
|---|---|---|
peripheral-bots.env | peripheral-bots.age | amc-peripheral systemd service |
backend.age | — | amc-backend NixOS container |
After modifying a plaintext secrets file, re-encrypt it from the secrets/ directory:
cd secrets
cat peripheral-bots.env | ragenix --editor - -e peripheral-bots.age
This pipes the plaintext into ragenix as the "editor" input, re-encrypting in place.
[!IMPORTANT] You must re-encrypt before deploying. The NixOS service reads the
.agefile, not the plaintext.env.
Secrets flow through: ragenix .age file → NixOS age.secrets → systemd EnvironmentFile → Python os.environ.get().
For amc-peripheral, this is configured in flake.nix:
age.secrets.peripheral-bots = {
file = ./secrets/peripheral-bots.age;
mode = "400";
};
services.amc-peripheral = {
environmentFile = config.age.secrets.peripheral-bots.path;
};