<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>age on tac lifelog</title>
    <link>https://tro3373.github.io/tags/age/</link>
    <description>Recent content in age on tac lifelog</description>
    <image>
      <title>tac lifelog</title>
      <url>https://tro3373.github.io/favicon.png</url>
      <link>https://tro3373.github.io/favicon.png</link>
    </image>
    <generator>Hugo -- gohugo.io</generator>
    <language>ja</language>
    <lastBuildDate>Tue, 06 Oct 2026 13:38:45 +0900</lastBuildDate><atom:link href="https://tro3373.github.io/tags/age/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>sops の暗号文・鍵・平文はどこに残るか</title>
      <link>https://tro3373.github.io/posts/2026/2026-10-06-sops-age-where-secrets-remain/</link>
      <pubDate>Tue, 06 Oct 2026 13:38:45 +0900</pubDate>
      
      <guid>https://tro3373.github.io/posts/2026/2026-10-06-sops-age-where-secrets-remain/</guid>
      <description>結論 sops のファイルは、値の暗号文を 1 つだけ持つ。受け取り手 (age の公開鍵) ごとの封筒と MAC は、同じファイルの sops メタデータに入る .sops.yaml が効くのは新規の暗号化だけ。既存ファイルの受け取り手は sops updatekeys を実行するまで変わらない 暗号化されるのは値とコメントで、キー名は平文で残る。MAC は既定で、暗号化していない値も覆う 復号鍵は 1 か所を選んで読むのではない。環境変数と ~/.config/sops/age/keys.txt など、見つかった鍵を全部足して試す 復号した平文は exec-env / exec-file で子プロセスへ渡せる。リポジトリに平文は残らないが、direnv_load は一時ファイルを経由し、同じユーザーのプロセスからは読める 以下は sops 3.13.3 / age v1.3.2 / direnv 2.37.1 で確かめた。 ソースの参照先は github.com/getsops/sops/v3@v3.13.3。
前提: 値はデータ鍵で 1 回だけ暗号化し、データ鍵を人数分の封筒に入れる sops はファイルを新しく暗号化するときにランダムなデータ鍵を 1 つ作り、値をそのデータ鍵で AES-256-GCM 暗号化する。 データ鍵は受け取り手それぞれの公開鍵で暗号化し (封筒)、ファイル末尾のメタデータに recipient (公開鍵) と enc (封筒) の組で並べる。 復号する側は、自分の秘密鍵で開けられる封筒を探してデータ鍵を取り出し、値を復号する。
データ鍵はファイルごとに 1 つで、sops edit で保存しても作り直さない。 編集の前後で封筒 (enc) は変わらず、触っていない値の暗号文も 1 文字も変わらなかった。変わるのは書き換えた値の暗号文だけ。 データ鍵を作り直すのは sops rotate だけ ( 後述 )。</description>
    </item>
    
  </channel>
</rss>
