{ keyCommandEnv, ... }:
{
  deployment.keys."searx-secret-key.secret" = {
    keyCommand = keyCommandEnv ++ [ "pass" "searx/secret-key" ];
    destDir = "/secrets";
    user = "root";
    group = "root";
    permissions = "0640";
    uploadAt = "pre-activation";
  };
}