smithery.ai

rekey-secrets

Re-encrypt all secrets after modifying .age files or changing host keys

First seen Apr 12, 2026

Installation

$ npx skills add https://smithery.ai

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from smithery.ai · top by installs.

npx skills add https://smithery.ai

Browse all from smithery.ai

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Skill metadata

Parsed from SKILL.md frontmatter.

Version1.0
CompatibilityRequires agenix, agenix-helper
More metadata
author
ruinous.ai
version
1.0
domain
secrets

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,528 B
  • docs SUMMARY.md 92 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 1 installs

SKILL.md

Rekey Secrets

Re-encrypt all secrets after modifying .age files or when host keys change.

When to use:

  • After creating or updating any .age file
  • After adding a new host to secrets.nix
  • After rotating host SSH keys

Prerequisites

# Unlock agenix before rekeying
just unlock

Steps

  1. Rekey all secrets:

``bash just rekey ``

  1. Stage and verify rekeyed files:

``bash git add secrets/ ls secrets/nixos/*/ ``

  1. Lock agenix when done:

``bash agenix-helper lock ``

Where Rekeyed Secrets Go

After agenix rekey -a, encrypted secrets are stored in:

secrets/nixos/<hostname>/<hash>-<secret_name>.age

Troubleshooting

Rekey fails with host errors

  • Check that all hosts in secrets.nix have valid keys
  • Verify host public keys are correct in the repository

Permission denied

# Ensure agenix is unlocked
just unlock

Example

# Unlock, rekey, and stage
just unlock
just rekey
git add secrets/

Post-Rekey Checklist

  • Ran just unlock before starting
  • All secrets rekeyed successfully (just rekey)
  • secrets/nixos/ contains updated files
  • Staged changes (git add secrets/)
  • No errors in output
  • Ran agenix-helper lock when done