一键导入
secrets-management
Managing ragenix-encrypted secrets in the AMC monorepo
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Managing ragenix-encrypted secrets in the AMC monorepo
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
| name | secrets-management |
| description | Managing ragenix-encrypted secrets in the AMC monorepo |
Secrets are stored as ragenix-encrypted .age files in the secrets/ directory. Plaintext .env files exist alongside their .age counterparts for editing convenience.
| Plaintext | Encrypted | Used by |
|---|---|---|
peripheral-bots.env | peripheral-bots.age | amc-peripheral systemd service |
backend.age | — | amc-backend NixOS container |
After modifying a plaintext secrets file, re-encrypt it from the secrets/ directory:
cd secrets
cat peripheral-bots.env | ragenix --editor - -e peripheral-bots.age
This pipes the plaintext into ragenix as the "editor" input, re-encrypting in place.
[!IMPORTANT] You must re-encrypt before deploying. The NixOS service reads the
.agefile, not the plaintext.env.
Secrets flow through: ragenix .age file → NixOS age.secrets → systemd EnvironmentFile → Python os.environ.get().
For amc-peripheral, this is configured in flake.nix:
age.secrets.peripheral-bots = {
file = ./secrets/peripheral-bots.age;
mode = "400";
};
services.amc-peripheral = {
environmentFile = config.age.secrets.peripheral-bots.path;
};
Building, packaging, and deploying MTDediMod releases (server and client mods)
Debugging crash dumps, PDB symbols, and UE4SS Lua GC issues in MTDediMod
SSH access to AMC servers and debugging amc-backend services