flyingcircusio / batou

batou is a universal, fractal deployment utility using Python.
https://batou.readthedocs.org
Other
47 stars 12 forks source link

age-based encryption - need general command to update/reencrypt all secrets in all environments #398

Closed ctheune closed 7 months ago

ctheune commented 9 months ago

Adding a new person requires to re-encrypt the files. AFAIK currently one has to edit (and change!) all environments to fetch updates for the keys end reencrypt and do that manually for all environments.

I think we need something like a secrets update command.

Also, there seems to be a bug with the existing add/remove commands (which are gpg-specific) and the "environments" parameter seems broken.

elikoga commented 7 months ago

I think this can fit in 2.4.1