This can be a simple nix-flake that exposes it's own modules. It'll be a good idea to rotate keys now due to "harvest now, decrypt later” practices.
Probably want to think about setting up an automation to handle this at some point. I'll give it a think later on.