Skip to content

Reading and writing secrets

All our committed secrets are stored in SOPS files. To read or write them you need two things: add your GPG key to the monorepo, and add it to the SOPS config file.

Reading

SOPS files can be opened directly. You can also fetch a secret config value with neph config get -e <env> SOME_KEY. That is a convenience wrapper around opening infra/inventory/<env>/config.yml with SOPS and finding SOME_KEY.

Writing

In order to write to SOPS files you will also need to import all GPG public keys. You can then edit them.