A better summary.
A better summary.
Posted Jun 15, 2026 1:27 UTC (Mon) by mathstuf (subscriber, #69389)In reply to: A better summary. by LtWorf
Parent article: Eliminating long-lived credentials with trusted publishing
For services with these kinds of things that they're "important" *and* require unencrypted passwords (I've migrated most everything else over to systemd-creds instead now), I instead store the relevant config file as a symlink to an automounted drive that is named through udev/udisks to a stable `/dev/mapper` name.
So, yes, still long-lived, but it doesn't need to be accessible just because I'm logged in (or even just booted as the common case may be).
