Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 29 additions & 2 deletions customer/signing-keys.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,34 @@ description: "Create and use signing keys to sign built artifacts"
---

In order to upload a package it must be signed, and in order to install a package published to a Flox Catalog you must configure your system to trust the public key used to sign the package.
By default, packages are signed with a key that's included with the Flox installer, so Flox is configured to be able to install user-published packages out of the box.
By default, packages published to FloxHub-hosted catalogs are signed with the `floxhub-1` key, which ships with the Flox installer, so Flox is configured to be able to install user-published packages out of the box.

If you installed Flox with Nix instead of the Flox installer — for example with `nix profile install`, or as part of a nix-darwin or NixOS configuration — your system doesn't have the `floxhub-1` key, and installing a package published to a FloxHub-hosted catalog fails with:

```text
Package 'my-package' is not signed by a trusted key.
See https://flox.dev/docs/customer/signing-keys/ for more information.
```

To fix this, add `floxhub-1` to your Nix configuration's trusted public keys, the same way you would [trust any other public key](#trust-a-public-key-to-install-published-artifacts).

If you're using a standalone Nix or Flox-installed Nix setup, add `floxhub-1` to the `extra-trusted-public-keys` line in `/etc/nix/nix.conf` (append to an existing line rather than adding a second one):

```text
extra-trusted-public-keys = <existing keys> floxhub-1:0QOAlcobcEvq1mqEf4qAYCaWnTTOXpyoRv/PmqfSixM=
```

Then [restart the Nix daemon](#add-a-new-trusted-key).

If your system is managed by NixOS or nix-darwin, add it to `nix.settings` instead, then rebuild and switch into your configuration:

```nix
nix.settings.extra-trusted-public-keys = [
"floxhub-1:0QOAlcobcEvq1mqEf4qAYCaWnTTOXpyoRv/PmqfSixM="
];
```

See the [generic Nix install instructions](/install-flox/install#generic-nix) for the full configuration examples, including the Flox binary cache key.

However, if you're providing your own Catalog Store, then you must

Expand Down Expand Up @@ -91,7 +118,7 @@ For systems whose configuration is managed with Nix, you need to add the public
For NixOS, `nix-darwin`, and `home-manager` the configuration option is the same:

```nix
nix.settings.trusted-public-keys = [
nix.settings.extra-trusted-public-keys = [
"<key contents>"
];
```
Expand Down
26 changes: 18 additions & 8 deletions install-flox/install.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -402,7 +402,7 @@ description: "How to install or upgrade the Flox CLI"

```bash title="/etc/nix/nix.conf"
extra-trusted-substituters = https://cache.flox.dev
extra-trusted-public-keys = flox-cache-public-1:7F4OyH7ZCnFhcze3fJdfyXYLQw/aV7GEed86nQ7IsOs=
extra-trusted-public-keys = flox-cache-public-1:7F4OyH7ZCnFhcze3fJdfyXYLQw/aV7GEed86nQ7IsOs= floxhub-1:0QOAlcobcEvq1mqEf4qAYCaWnTTOXpyoRv/PmqfSixM=
```

Then restart the `nix-daemon`, if applicable:
Expand Down Expand Up @@ -463,7 +463,7 @@ description: "How to install or upgrade the Flox CLI"

```bash title="/etc/nix/nix.conf"
extra-trusted-substituters = https://cache.flox.dev
extra-trusted-public-keys = flox-cache-public-1:7F4OyH7ZCnFhcze3fJdfyXYLQw/aV7GEed86nQ7IsOs=
extra-trusted-public-keys = flox-cache-public-1:7F4OyH7ZCnFhcze3fJdfyXYLQw/aV7GEed86nQ7IsOs= floxhub-1:0QOAlcobcEvq1mqEf4qAYCaWnTTOXpyoRv/PmqfSixM=
```

Or, to your flake configuration by using the `nixConfig` attribute.
Expand All @@ -473,7 +473,10 @@ description: "How to install or upgrade the Flox CLI"
{
nixConfig = {
extra-trusted-substituters = ["https://cache.flox.dev"];
extra-trusted-public-keys = ["flox-cache-public-1:7F4OyH7ZCnFhcze3fJdfyXYLQw/aV7GEed86nQ7IsOs="];
extra-trusted-public-keys = [
"flox-cache-public-1:7F4OyH7ZCnFhcze3fJdfyXYLQw/aV7GEed86nQ7IsOs="
"floxhub-1:0QOAlcobcEvq1mqEf4qAYCaWnTTOXpyoRv/PmqfSixM="
];
};
}
```
Expand All @@ -487,7 +490,10 @@ description: "How to install or upgrade the Flox CLI"

nixConfig = {
extra-trusted-substituters = ["https://cache.flox.dev"];
extra-trusted-public-keys = ["flox-cache-public-1:7F4OyH7ZCnFhcze3fJdfyXYLQw/aV7GEed86nQ7IsOs="];
extra-trusted-public-keys = [
"flox-cache-public-1:7F4OyH7ZCnFhcze3fJdfyXYLQw/aV7GEed86nQ7IsOs="
"floxhub-1:0QOAlcobcEvq1mqEf4qAYCaWnTTOXpyoRv/PmqfSixM="
];
};

inputs = {
Expand All @@ -513,11 +519,12 @@ description: "How to install or upgrade the Flox CLI"

nix.settings = {
experimental-features = "nix-command flakes";
substituters = [
extra-substituters = [
"https://cache.flox.dev"
];
trusted-public-keys = [
extra-trusted-public-keys = [
"flox-cache-public-1:7F4OyH7ZCnFhcze3fJdfyXYLQw/aV7GEed86nQ7IsOs="
"floxhub-1:0QOAlcobcEvq1mqEf4qAYCaWnTTOXpyoRv/PmqfSixM="
];
};

Expand All @@ -542,8 +549,11 @@ description: "How to install or upgrade the Flox CLI"
On NixOS, configure `/etc/nixos/configuration.nix` to add the lines:

```text title="/etc/nixos/configuration.nix"
nix.settings.trusted-substituters = [ "https://cache.flox.dev" ];
nix.settings.trusted-public-keys = [ "flox-cache-public-1:7F4OyH7ZCnFhcze3fJdfyXYLQw/aV7GEed86nQ7IsOs=" ];
nix.settings.extra-trusted-substituters = [ "https://cache.flox.dev" ];
nix.settings.extra-trusted-public-keys = [
"flox-cache-public-1:7F4OyH7ZCnFhcze3fJdfyXYLQw/aV7GEed86nQ7IsOs="
"floxhub-1:0QOAlcobcEvq1mqEf4qAYCaWnTTOXpyoRv/PmqfSixM="
];
```

... and then invoke:
Expand Down
3 changes: 2 additions & 1 deletion install-flox/troubleshooting.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -377,6 +377,7 @@ nix.settings = {
extra-substituters = [ "https://cache.flox.dev" ];
extra-trusted-public-keys = [
"flox-cache-public-1:7F4OyH7ZCnFhcze3fJdfyXYLQw/aV7GEed86nQ7IsOs="
"floxhub-1:0QOAlcobcEvq1mqEf4qAYCaWnTTOXpyoRv/PmqfSixM="
];
};
```
Expand All @@ -385,7 +386,7 @@ Or directly in `/etc/nix/nix.conf`:

```ini
extra-substituters = https://cache.flox.dev
extra-trusted-public-keys = flox-cache-public-1:7F4OyH7ZCnFhcze3fJdfyXYLQw/aV7GEed86nQ7IsOs=
extra-trusted-public-keys = flox-cache-public-1:7F4OyH7ZCnFhcze3fJdfyXYLQw/aV7GEed86nQ7IsOs= floxhub-1:0QOAlcobcEvq1mqEf4qAYCaWnTTOXpyoRv/PmqfSixM=
```

Verify the change took effect:
Expand Down
Loading