Security and Trust¶
Trust boundaries, sandboxes, secrets, and signing.
Contents¶
- Supply Chain — Dependency and build trust
- Trusted Users — Trust model for the daemon
- Sandbox Escape Surface — Build sandbox boundaries
- Secrets Management — Keeping secrets out of the store
- SSH and age plugins — Host keys, age plugins, YubiKey patterns
- Signing and Caches — Signed binary caches
- AppArmor and SELinux — MAC frameworks on NixOS (maturity-stamped)
- Reproducible builds audit —
--check/--rebuild, diffoscope, what “reproducible” means - Inter-machine trust — Fleet/mesh trust axes (reachability, build, binary, deploy, secrets, supply chain)