updates instructions - archive

ADP-216_sops_automation
LeeW 10 months ago
parent 630dbb6732
commit 48f845dde7

@ -123,23 +123,25 @@ To mark a key as expired:
```shell ```shell
# archive key - DO NOT delete - need this for auditing # archive key - DO NOT delete - need this for auditing
git mv ${keyname} "archive/${keyname}_$(date '+%Y-%m-%d').archive" git mv ${keyname} "archive/${keyname}_$(date '+%Y-%m-%d').archive"
# remove from verification sops
# list all groups ./verify/usr_confirm_keycfg.sh
find groups -name ${keyname} | xargs git rm
``` ```
### 2. For each group / repo: ### 2. For each group / repo:
**Prerequisite**: Local copy of repo **Prerequisite**: Local copy of each repo corresponding to a group
```shell ```shell
# For a given group, update sops config # list all groups to which the key is registered
find groups/ -name ${keyname}
# For each group, update sops config in that repo
# Example: # Example:
% cd devnso-adp-argocd % cd devnso-adp-argocd
% ${PATH_TO_THIS_REPO}/bin/update_sops.sh -g devnso-adp-argocd % ${PATH_TO_THIS_REPO}/bin/update_sops.sh -g devnso-adp-argocd
# now git commit, push, etc
``` ```
### 3. This repo: update groups ### 3. This repo: update groups
```shell ```shell
# remove from groups # remove from groups

Loading…
Cancel
Save