10 ms·
Show HN: SecretCrypt – Keeping secrets in plain sight
- brudgers 10y agoRepository: https://github.com/Zemanta/go-secretcrypt https://github.com/Zemanta/go-secretcrypt
- web007 10y agoUsing KMS is a good idea, but I'm not really sure what this package gives you - just a simple abstraction / cmdline to deal with it? This would be better if it could use the aliases directly, so you could have one config across N environments and separate them by AWS keyspace. Having to embed the full KMS path for each key gains you the secret management they claim (which is a good thing) but sacrifices ease of use. That said, aliases wouldn't help with missing secrets or misconfiguration across environments, and its a lot easier to audit string-for-string to match your KMS store, so either approach has its pluses and minuses.
- otterley 10y agoIt should be made clear that this requires AWS KMS, and for automatic decryption, EC2 (so that the instances can be associated with an IAM role that has key decryption permission).
- daenney 10y agoI think that's pretty clear in the article that's linked. It explicitly mentions AWS KMS and its reliance on it and how IAM roles are used to grant access to a secret. It also states that KMS isn't a requirement, you can use Vault too.
- koolba 10y ago> Since the configuration file is kept in the same repository as the code, configuration options or secrets can easily be changed or added by developers themselves. This is terrible advice. Code and config should be separate. Otherwise you can't deploy the same code to a different environment.
- NickBusey 10y agoYup. Storing config and code together is a violation of the Twelve-Factor App methodology. https://12factor.net/config https://12factor.net/config
- sleepychu 10y agoIs this methodology accepted as state of the art or used by the author of this article? I don't see why breaking this particular set of rules is an issue.
- mafro 10y agoI keep hearing this "violation of Twelve-Factor" statement. The Twelve-Factor Methodology is a sensible set of guidelines/defaults for building a modern app, as written by Heroku. Don't blindly follow it As It Was Written without thinking. Seriously, do what works. Use your brain. Using this statement as an argument against other methods is sending the wrong message.
- andreasklinger 10y agowhat's your counter argument/proposal ?
- hueving 10y agoThey are just guidelines. "violating them" means absolutely nothing so claiming so adds nothing to the conversation.
- mafro 10y agoThis is exactly what I meant.
- nickpsecurity 10y agoHere's my interpretation of the link: https://news.ycombinator.com/item?id=12344971 https://news.ycombinator.com/item?id=12344971
- Gaelan 10y agoThe "write-only" feature could be implemented without a third-party with a keypair.
- Gaelan 10y agoThe "write-only" feature could be implemented without a third-party with a keypair.
- whyleyc 10y agoWhat happens if Amazon's KMS service is down - does that break the app or can you operate ok without it ?
- hamax 10y agoWe decided to decrypt secrets on service startup so if KMS is down during the deploy we can stop the deploy after first server fails to start. Not perfect but good enough for our use case. In case of catastrophic KMS failure we can always manually replace secrets with plaintext and revoke them afterwards.
- chrisdotcode 10y agoHow is this different from/better than Stack Exchange's blackbox[0] which doesn't require a third-party service (just plain-ole gpg) and is written in bash? [0] https://github.com/StackExchange/blackbox https://github.com/StackExchange/blackbox P.S.: I think the image looks aesthetically pleasing, but why is it there? It's a scaled-down 1,600x680px image that costs me 140KB and doesn't add anything to the article; what's worse is that it's not even a nice banner image, it's just smack dab in the middle of the article.
- yayitswei 10y agoThat's the company logo, so it's the ad that makes this blog post possible.
- justinlardinois 10y ago> image that costs me 140KB What year is it?
- Esau 10y agoThat's besides the point. Wasted bandwidth should be avoided.
- jbb555 10y agoSo... storing your secrets in AWS then... and not in plain sight.
- cheeze 10y agoYeah, that wording is odd. Storing your secrets in plain sight* * as long as plain sight includes a remote service call at some point
- 45h34jh53k4j 10y agoI like this design. Infrastructure as code. Store your config data in you repo. Screw 12 factors. You can do this with the inhouse AWS tools, awscli and boto3 for python This was for use within a python lambda function so i used the secrets in a seperate file, but no loss of generality here. * Create your keys in KMS via Web UI or otherwise * encrypt your secrets before commit aws kms encrypt --key-id alias/TokenKey --plaintext fileb://unencrypted_token --output text --query CiphertextBlob > encrypted_token Decrypt the token from your python lambda function with boto3 kms = boto3.client('kms') token = kms.decrypt(CiphertextBlob=base64.b64decode(token_encrypted))['Plaintext'].decode('ascii') The blob from KMS contains the appropriate fields for decryption from their service. Give the lambda role rights to decrypt with the key.