Use a template-based configuration management system to pull in secrets from a secrets management system (passwords/credentials/PKI management). It's an antipattern to add even more complexity by bolting on configuration or secrets management as part of nix, systemd, or anything else that's OS- or distro-specific. Package managers, and OSes need to offer sane defaults but then have sensible boundaries and allow configuration responsibility to be delegated to users and/or configuration management.
eviks•50m ago
How would that help if the result of the template is the same single config file that doesn't separate concerns?
eqvinox•2h ago
Who other than nixOS has this problem? Feels like a nixOS thing to me, which I'm not going to complicate my applications for. All the orchestration tools have something like a vault, don't they?
burnt-resistor•5h ago
eviks•50m ago