- https://docs.puppetlabs.com/hiera/1/custom_backends.html
- https://puppetlabs.com/blog/encrypt-your-data-using-hiera-eyaml
- https://packages.debian.org/jessie/hiera-eyaml
- - how to distribute keys outside the repo (i.e, avoiding all nodes to have all keys?):
+ - key deployment
- add a monkeysphere auth subkey to every openpgp key used for backups.
- make backupninja wrap around monkeysphere: http://web.monkeysphere.info/doc/user-ssh-advanced/
- http://current.workingdirectory.net/posts/2011/puppet-without-masters/