From 2b61601dd95244e31d82613621955effb91f7222 Mon Sep 17 00:00:00 2001 From: Franck Cuny Date: Fri, 28 Nov 2025 14:05:44 -0800 Subject: add a module to remotely unlock machines For machines with full disk encryption, we can remotely unlock them from bree. A systemd timer will run every 10 minutes and check if we need to unlock the host. If we need to, it will SSH and provide the passphrase to unlock the disk(s). --- secrets/bree/disk-passphrase.age | 8 ++++++++ 1 file changed, 8 insertions(+) create mode 100644 secrets/bree/disk-passphrase.age (limited to 'secrets/bree/disk-passphrase.age') diff --git a/secrets/bree/disk-passphrase.age b/secrets/bree/disk-passphrase.age new file mode 100644 index 0000000..3811173 --- /dev/null +++ b/secrets/bree/disk-passphrase.age @@ -0,0 +1,8 @@ +age-encryption.org/v1 +-> ssh-ed25519 pFjJaA r/Q4nB/VcKaVXoJjDuIgnMVUr5K0rhrsVVq2lvQgQRQ +ZmwHs0sWxVKjS9njqPQR4rEV1aXxS80wWJQrAuf47vM +-> ssh-ed25519 OxmK1A /9e7fHg/Nh929cY7+0EagkxwME4jo0RxzBwdh8tuZnM +9UPI8Vnwebjick9WPlcT8lvNub687qchX4D4ntbanos +--- bwBCnL9gJhzuygCddmh0h0OXh/C6ysAgMfH9QBrQUMY + +I4ڍ:;X3T.n{A0^笆4F]P.uΕެ \ No newline at end of file -- cgit v1.2.3