3 ms·
It has been a while but the issues that are coming to mind are: - A (semver) patch version after 1.13.0 made a backwards incompatible change to the way the hmac
by jwineinger 8y ago
It has been a while but the issues that are coming to mind are:
- A (semver) patch version after 1.13.0 made a backwards incompatible change to the way the hmac field was stored in dynamo, IIRC. This broke older versions and alternative implementations (jcredstash) ability to read secrets stored by newer versions. IIRC it was some double base64-encoding issue or something like that.
- Early versions of credstash didn't use zero padded version numbers, and then later versions switched. This was documented but still caused some headaches.
- Recently coworkers have made some noise about incompatibility with python3. I haven't had a chance to evaluate that though.
Not a breakage, but annoyance:
- Lack of handling pagination for dynamo queries so you only get a list of the secrets+versions that are returned in the first page of results. We don't need to list all that often, but when you do... (rage). I would end up having to make queries against the dynamo table itself to find available secret names or versions.
Finally, it is much slower than using SSM parameters. It was a usable but warty tech for a while, but now that AWS has native support for storing secrets there seems little reason to continue with it.