4 ms·
I see quite a few posts discussing running Postgres in a separate VPC or network. We currently run our Postgres databases within Kubernetes and leverage networ
by SomaticPirate 6y ago
I see quite a few posts discussing running Postgres in a separate VPC or network.
We currently run our Postgres databases within Kubernetes and leverage network policies to ensure that only application pods can access the database.
The application pods ingest the db credentials from Vault. The biggest concern we have today is automating credential rotation.
Curious if anyone else has a similar setup or thoughts on ours?
- imglorp 6y agoVault has a nice trick where they can create a temporary DB credential to hand to clients. If that cred is stolen, it's no good later. You have to convince Vault to give you a new cred if you want to talk to the DB. https://www.hashicorp.com/resources/securing-databases-with-dynamic-credentials-vault https://www.hashicorp.com/resources/securing-databases-with-...