You can backup your config files before editing them, like this:

cp configbeingedited.conf configbeingedited.conf__orig_datestring

This way, when things break or don’t function how you like, you can easily copy the original config file back into position, restoring the original functionality.

  • astral_avocado@programming.dev
    link
    fedilink
    arrow-up
    5
    ·
    11 months ago

    I generally keep my config files stored in the GitHub repo for version control, and then actual secrets are pulled dynamically from a secret store.

      • astral_avocado@programming.dev
        link
        fedilink
        arrow-up
        1
        ·
        11 months ago

        Specifically AWS secrets manager, I know there’s others like if you’re using Ansible there’s Ansible Vault. The point is that it’s a separate service that keeps all your secrets encrypted at rest and to access them you need an initial authentication.

        • zlatko@programming.dev
          link
          fedilink
          arrow-up
          3
          ·
          11 months ago

          I’ve been meaning to get the ansible thing. Not for my home computers, my dotfiles are on GitHub, SSH keys offline, stuff backed up. But I always think that if my poor hetzner box dies, I’ll have a lot of fun getting it all back up :/

          • astral_avocado@programming.dev
            link
            fedilink
            arrow-up
            2
            ·
            11 months ago

            😂 Honestly Ansible can be a little obtuse at times, I’m having a much better time with having all my stuff defined in Docker and deployed via docker-compose or Terraform for non-self-hosted stuff. Ansible can be a lot of effort but I can also see it being better in the long run.

            Then there’s the NixOS people… people swear by that. I haven’t dived into that whole world yet.

            • zlatko@programming.dev
              link
              fedilink
              arrow-up
              2
              ·
              11 months ago

              Yeah NixOS is my other alternative, but I think that rabbit hole is much more deep than the Ansible one :)

              I also manage my few self-hosted things and play-things with docker-compose on my box, but who manages docker-compose files? :) And nginx config, and network-related stuff etc etc. I am too lazy but I guess I will have to bite the bullet and after 20 years of manually doing it all and backing up raw and praying, actually figuring out the next level.

    • wackoCamel@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      11 months ago

      I tend to make a .bak file before changes. There is nothing worse than fixing one config item only to realize later something else broke and not being sure what it was that changed and no easy way to revert. I’m guilty of having many .bak configs that are poorly named. I hadn’t heard of etckeeper before. That looks real handy for me. Thanks for sharing

    • ace_garp@lemmy.worldOP
      link
      fedilink
      arrow-up
      2
      ·
      11 months ago

      This is a clean way to make your own new command called ‘bak’, to automate making a second copy of the file.