Public Dotfiles, Private Secrets: My Nix OS Docker Workflow

For the longest time I ran every container in my homelab on Proxmox. It did the job, but because I use NixOS on my main workstation and NixDarwin on my laptop, I eventually wanted the lab to follow the same declarative model. A few months ago I switched those machines to NixOS as well. Everything went smoothly except for one thing: moving the containers themselves.

The problem was secrets. I keep my entire configuration, including the lab, in a public dotfiles repository. Many of the containers need tokens such as Cloudflare, API keys, you name it, that obviously must not end up on GitHub. Every time I sat down to migrate the stack I put it off for this single reason.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论