Reading and writing secrets
All our committed secrets are stored in SOPS files. To read or write them you need two things: add your GPG key to the monorepo, and add it to the SOPS config file.
Reading
SOPS files can be opened directly.
You can also fetch a secret config value with
neph config get -e <env> SOME_KEY. That is a convenience wrapper around
opening infra/inventory/<env>/config.yml with SOPS and finding SOME_KEY.
Writing
In order to write to SOPS files you will also need to import all GPG public keys. You can then edit them.