5 ms·
We are working on a solution to this problem in the Clevis project[0]. It is a basic FUSE filesystem that will transparently decrypt your secrets/configuration.
by npmccallum 9y ago
We are working on a solution to this problem in the Clevis project[0]. It is a basic FUSE filesystem that will transparently decrypt your secrets/configuration. It will evaluate your decryption policy on each open and log the attempt.
You can see the initial proof of concept[1]. It isn't secure yet, for a variety of reasons. But it is enough to play around with. Moving to a better encryption scheme will give us the ability to do locks and per-block validation.
[0]: https://github.com/latchset/clevis https://github.com/latchset/clevis
[1]: https://github.com/npmccallum/clevis/blob/fuse/src/clevis-fuse.c https://github.com/npmccallum/clevis/blob/fuse/src/clevis-fu...