Each box now has its own per-machine age key at ~/.config/chezmoi/key.txt. The .age file is encrypted to all 6 recipients, so any of them can decrypt zai.key on next chezmoi apply. Implementation note: chezmoi only honors the LAST --age-recipient flag when given multiple. Use --age-recipient-file=path/to/file (one pubkey per line) for multiple recipients in a single call. |
||
|---|---|---|
| .. | ||
| config.yml | ||
| mcp.json | ||
| zai.key.age | ||