Manage agenix-encrypted secrets in the NixOS repository at ~/nixos. Use when: adding a new secret for a NixOS service, changing which hosts can decrypt a secret, rekeying secrets after host changes, or wiring secrets into NixOS modules/systemd services. Triggers on mentions of agenix, age secrets, encrypted secrets, secret management, or adding credentials/passwords/keys for NixOS services.
2026-06-09