{ keyCommandEnv, ... }:
{
  deployment.keys."signing-key.secret" = {
    keyCommand = keyCommandEnv ++ [ "pass" "hydra/signing-key" ];
    destDir = "/secrets";
    user = "root";
    group = "root";
    permissions = "0640";
    uploadAt = "pre-activation";
  };
}