Load a config that has no age recipient (closes #221)
check / check (push) Successful in 13m47s
check / check (push) Successful in 13m47s
The README's steps for restoring on another machine failed at the first command: `config init` wrote a placeholder recipient, and `config.Load` rejects any recipient that does not parse. `config init` now writes an empty `age_recipients` list, `config.Load` accepts an empty list, and `snapshot create` refuses to start without a recipient. A malformed recipient is still rejected at load. The recovery-host test now builds its config with `config init` and `config set` and reads it through `config.Load`, so it imports `internal/cli`. On a fresh file, `config set age_recipients.0` writes the list in flow style (`[age1...]`). Model: opus-5-5
This commit was merged in pull request #244.
This commit is contained in:
@@ -530,7 +530,7 @@ complete annotated example also lives in
|
||||
|
||||
| Field | Default | Description |
|
||||
|-------|---------|-------------|
|
||||
| `age_recipients` | (required) | Age public keys for encryption |
|
||||
| `age_recipients` | (required by `snapshot create`) | Age public keys for encryption. Other commands run without one, so a machine that only restores can leave it empty |
|
||||
| `age_secret_key` | (unset) | Age private key for decryption (`snapshot restore`, `snapshot verify --deep`). Setting it in the config file places the private key on the backed-up host, defeating the public-key-only design (see "why" above). Prefer the `VAULTIK_AGE_SECRET_KEY` environment variable, supplied only on the machine you restore from. |
|
||||
| `snapshots` | (required) | Named snapshot definitions with paths and excludes |
|
||||
| `storage_url` | | Storage backend URL (`s3://`, `file://`, `rclone://`) |
|
||||
|
||||
Reference in New Issue
Block a user