3 ms·
Funny how hashicorp promotes security products on one hand and fails to implement proper security in their remaining products on the other hand. For instance:
by t-moe 8y ago
Funny how hashicorp promotes security products on one hand and fails to implement proper security in their remaining products on the other hand.
For instance: Vagrant Images/boxes hosted by hashicorp (vagrantcloud) are neither signed nor is there any author information available (if not explicitly provided by the uploader).
- kgilpin 8y agoAlso, Terraform stores "all settings, including usernames, passwords, port numbers and literally everything else" in the tfstate file (1). I believe that using Dynamic Secrets is HashiCorp's proposal for how to mitigate this; leave the secrets in the log files, but make sure they expire in a timely manner. [1] https://tosbourn.com/hiding-secrets-terraform/ https://tosbourn.com/hiding-secrets-terraform/
- jugg1es 8y agoYea, I wish they had thought of sensitive stuff in the state files from the beginning.