name: secrets-sync description: "Use when the user adds, edits, lists, or applies chezmoi-managed secrets; syncs Bitwarden sessions; runs GPG encryption on project files; or works with the .secrets submodule. Also use when troubleshooting chezmoi config path issues in this repository."
secrets-sync
All chezmoi commands in this repo require --config ./.chezmoi.toml because the config is project-local, not in ~/.config/chezmoi.
Source-of-Truth Chain
digraph secrets {
rankdir=LR;
node [shape=box];
"Bitwarden" -> ".env.bitwarden" -> "chezmoi templates\n(.secrets/)";
"chezmoi templates\n(.secrets/)" -> "chezmoi apply" [shape=plaintext];
"chezmoi apply" -> "target files\n(project root)";
}
Quick Reference
| Operation | Command |
|---|---|
| Add new secret | ./dotfile-utils/scripts/chezmoi-add-secret.sh [--encrypt] <path> |
| Edit existing secret | Edit file in place, then chezmoi --config ./.chezmoi.toml merge <path> to sync back to source |
| List managed files | chezmoi --config ./.chezmoi.toml managed |
| Apply secrets | chezmoi --config ./.chezmoi.toml apply |
| Check diff | chezmoi --config ./.chezmoi.toml diff |
| Source Bitwarden | source ./dotfile-utils/scripts/source_bitwarden_session.sh |
| Stage in submodule | chezmoi --config ./.chezmoi.toml git -- add <chezmoi-path> |
Workflow
- Determine operation: add / edit / list / apply
- If working with encrypted or Bitwarden-templated secrets, source the Bitwarden session first (auto-sourced by helper script when
.env.bitwardenexists orBW_SESSIONis set) - Run the correct command from the table above
- Verify with
managedordiff - Stage changes inside
.secretssubmodule - Remind user to commit the updated submodule pointer in the parent repo
Key Facts
- Config flag required: Every
chezmoiinvocation needs--config ./.chezmoi.toml - GPG key ID:
9A4ABBA2F90BCF19 .secretsis a git submodule -- changing files inside it means the parent repo sees a dirty submodule pointer that must also be committedchezmoi-add-secret.shhandles dot-prefix conversion (.env->dot_env) andencrypted_prefix automatically; it also auto-sources Bitwarden if.env.bitwardenexists- Source dir:
.secrets/(set viasourceDirin.chezmoi.toml) - Dest dir: project root
.(set viadestDirin.chezmoi.toml)
Common Mistakes
- Running bare
chezmoiwithout--config ./.chezmoi.toml(will use~/.config/chezmoiand operate on the wrong source) - Forgetting to commit the submodule pointer in the parent repo after changing
.secrets - Using
chezmoi adddirectly instead ofchezmoi-add-secret.shfor project files (chezmoi refuses to add files from its own dest dir)
Architecte Docker Compose
DevOps
Concoit des configurations Docker Compose optimisees.
Rapport de Post-Mortem
DevOps
Rédige des rapports post-mortem d'incidents structurés et blameless.
Créateur de Runbooks
DevOps
Crée des runbooks opérationnels clairs pour les procédures DevOps courantes.