Skip to content

feat: configure encrypted OpenCode credentials - #157

Merged
ajaxbits merged 1 commit into
mainfrom
feat/grace-editor-opencode-password
Sep 6, 2026
Merged

feat: configure encrypted OpenCode credentials#157
ajaxbits merged 1 commit into
mainfrom
feat/grace-editor-opencode-password

Conversation

@ajaxbits

@ajaxbits ajaxbits commented Sep 6, 2026

Copy link
Copy Markdown
Owner

Summary

  • add an agenix-encrypted OpenCode environment file for the Grace editor
  • mount only that secret directory read-only into the guest
  • configure the OpenCode systemd service to consume it

Validation

  • complete patroclus NixOS configuration evaluation
  • verified the encrypted secret decrypts using the patroclus SSH host identity, without printing its contents
  • verified the guest service resolves the expected EnvironmentFile and read-only VirtioFS share

The service will use the stable credentials after this PR is deployed and microvm@grace-editor is restarted.

@ajaxbits
ajaxbits force-pushed the feat/grace-editor-opencode-password branch from a742833 to 5d50c64 Compare September 6, 2026 23:44
@ajaxbits
ajaxbits merged commit 0f5ad41 into main Sep 6, 2026
1 check passed
@ajaxbits

ajaxbits commented Sep 7, 2026

Copy link
Copy Markdown
Owner Author

Superseded by #158, rebased onto deployed #156 and fixing the secret-file materialization required for the guest VirtioFS share.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant