{ keyCommandEnv, ... }: { deployment.keys = { "keycloak-database-password.secret" = { keyCommand = keyCommandEnv ++ [ "pass" "keycloak/database-password" ]; destDir = "/secrets"; user = "root"; group = "systemd-network"; permissions = "0640"; uploadAt = "pre-activation"; }; }; }