# Secrets Burrow secrets live in `secrets/.age` and are managed with `agenix`. For the Forgejo Namespace Cloud runtime: - `secrets/forgejo/admin-password.age` - `secrets/forgejo/agent-ssh-key.age` - `secrets/forgejo/nsc-token.age` - `secrets/forgejo/nsc-dispatcher-config.age` - `secrets/forgejo/nsc-autoscaler-config.age` Use: - `make secret name=forgejo/nsc-token` - `make secret-file name=forgejo/agent-ssh-key file=/path/to/source` The forge host decrypts these files at activation time and feeds the resulting paths into `services.burrow.forge`, `services.burrow.forgeRunner`, and `services.burrow.forgejoNsc`.