Skip to content

REQ: external secret management #279

Locked Answered by j-zimnowoda
j-zimnowoda asked this question in Q&A
Discussion options

You must be logged in to vote

User stories

  1. A user can define external-secret in values repo: #317
  2. A user can define external-secret in otomi-console: https://github.com/redkubes/otomi-console/issues/58 linode/apl-api#131
  3. An admin can bootstrap otomi-core internal secrets

System requirements

Vault security

  1. The Vault seal is configurable
  2. The vault encryption key is periodically rotated
  3. The Vault defines access polices that restrict access to certain paths
  4. The vault perform periodically encryption key rotation
  5. The Kubernetes Service Account token is used for authentication at Vault
  6. The Kubernetes Service Account name has associated vault policy
  7. The Kubernetes Service Account name is unique for each deployed chart/app …

Replies: 12 comments 28 replies

Comment options

You must be logged in to vote
1 reply
@j-zimnowoda
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
3 replies
@j-zimnowoda
Comment options

@Morriz
Comment options

@j-zimnowoda
Comment options

Comment options

You must be logged in to vote
2 replies
@j-zimnowoda
Comment options

@0-sv
Comment options

Comment options

You must be logged in to vote
3 replies
@Morriz
Comment options

@j-zimnowoda
Comment options

@Morriz
Comment options

Comment options

You must be logged in to vote
1 reply
@j-zimnowoda
Comment options

Comment options

You must be logged in to vote
3 replies
@j-zimnowoda
Comment options

@Morriz
Comment options

@j-zimnowoda
Comment options

Comment options

You must be logged in to vote
6 replies
@0-sv
Comment options

@j-zimnowoda
Comment options

@0-sv
Comment options

@Morriz
Comment options

@j-zimnowoda
Comment options

Comment options

You must be logged in to vote
2 replies
@Morriz
Comment options

@j-zimnowoda
Comment options

Comment options

You must be logged in to vote
3 replies
@Morriz
Comment options

@Morriz
Comment options

@j-zimnowoda
Comment options

Comment options

You must be logged in to vote
4 replies
@j-zimnowoda
Comment options

@Morriz
Comment options

@j-zimnowoda
Comment options

@j-zimnowoda
Comment options

Comment options

You must be logged in to vote
0 replies
Answer selected by j-zimnowoda
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants