4 ms·
I hope vendors like DigitalOcean would provide more fine tuned access controls in their APIs. Certbot, which I have setup to automatically renew my wildcard Le
by ypolito 8y ago
I hope vendors like DigitalOcean would provide more fine tuned access controls in their APIs.
Certbot, which I have setup to automatically renew my wildcard Let's Encrypt certificates, has access to my master API key on DO. I try to follow the best practices in keeping it safe, but I'd prefer if that specific API key would only have the required privileges to modify a set of specifically named TXT records and nothing more.
- geggam 8y agouse AWS and IAM roles like civilized folk
- regecks 8y agoRoute53/IAM doesn't have any way to restrict access to only _acme-challenge DNS labels. Use RFC2136 like civilized folk, I guess. ¯\_(ツ)_/¯
- bashinator 8y agoI'm a little surprised that route53 IAM policies aren't granular enough to restrict access to specific records or record types. It seems obvious that a service (lambda or such) should be able to issue cert autorenewal records without any other route53 access, and I wouldn't be surprised if this were already on a roadmap.
- Avamander 8y agoWish it supported all my TLDs.