cc-ci-secrets now also encrypts to the new host (195.201.88.249) via its ssh-host-key-derived age identity (age1tmvg…), like the canonical cc-ci did, so the off-box master recovery key no longer has to live on that box. .sops.yaml here updated to match; submodule pointer bumped to cc-ci-secrets 638c28d.
cc-ci-secrets now also encrypts to the new host (195.201.88.249) via its ssh-host-key-derived age identity (`age1tmvg…`), like the canonical cc-ci did, so the off-box master recovery key no longer has to live on that box. `.sops.yaml` here updated to match; submodule pointer bumped to cc-ci-secrets 638c28d.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
cc-ci-secrets now encrypts to the new host (195.201.88.249) via its own
ssh-host-key-derived age identity, like the canonical cc-ci did, so the
off-box master recovery key no longer has to live on that box —
/var/lib/sops-nix/key.txt there holds the host-derived identity instead.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
cc-ci-secrets now also encrypts to the new host (195.201.88.249) via its ssh-host-key-derived age identity (
age1tmvg…), like the canonical cc-ci did, so the off-box master recovery key no longer has to live on that box..sops.yamlhere updated to match; submodule pointer bumped to cc-ci-secrets 638c28d.🤖 Generated with Claude Code
https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz