5 ms·
Didn't he already do this? https://github.com/kelseyhightower/vault-controller https://github.com/kelseyhightower/vault-controller
by coleca 10y ago
Didn't he already do this? https://github.com/kelseyhightower/vault-controller https://github.com/kelseyhightower/vault-controller
- otterley 10y ago"This is a prototype. Do not use this in production." Also, it's just a start; the existing "secrets" implementation needs to be completely scrapped in the name of security.
- metral 10y agoAdding integration of Vault into Secrets is an active discussion in sig-auth: https://github.com/kubernetes/kubernetes/issues/10439#issuecomment-263954184 https://github.com/kubernetes/kubernetes/issues/10439#issuec... If you'd like to participate in these discussions, here are the details for the sig-auth's meetings & agenda items: https://github.com/kubernetes/community/tree/master/sig-auth https://github.com/kubernetes/community/tree/master/sig-auth
- otterley 10y agoThanks!
- elsonrodriguez 10y agoA prototype is a great way to get the conversation started. Most people don't even know why Vault should be considered, let alone why it's better than K8s secrets (which in their world works fine).
- otterley 10y agoI agree, it's a start. At its core, I'm having some difficulty wrapping my brain around the idea that any organization that's large and complex enough to demand to run their own compute platform (e.g. K8S) isn't also large and complex enough to demand a secure configuration system by default.
- meddlepal 10y agoFines are cheap. Engineering is expensive. There's your answer. I don't like it any more than you do, but that's the world we live in.
- otterley 10y agoIt's not just fines; it's the potential loss of your certifications upon which customers condition their business. That's a Big Deal.
- iamdeedubs 10y agoMaybe that's the disconnect here. There are plenty of small orgs using kubernetes for the ease of use and portability