3 ms·
In Kubernetes, secrets are base64 encoded, so they are quite secure. I’m sorry, but what the actual f&$/… I‘s expect better from RedHat. In what world does sto
by MadsRC 5y ago
In Kubernetes, secrets are base64 encoded, so they are quite secure.
I’m sorry, but what the actual f&$/… I‘s expect better from RedHat. In what world does storing a secret as base64 warrant calling it “quite secure”?
The only protection I can think of is:
* The occasional glance at your screen.
* Injection attack (to some degree)
- gravypod 5y agoI think the main reason for base64 encoding is to allow you to store binary data into a secret. Not a security measure. The kubernetes docs say as much: https://kubernetes.io/docs/concepts/configuration/secret/ https://kubernetes.io/docs/concepts/configuration/secret/
- jbeda 5y agoCan confirm this is why we did it. Very confused to see Red Hat claim that Base64 was a security thing.
- smarterclayton 5y agoI’m pretty sure the author just wasn’t as familiar with the topic as they should have been. Should have been caught during editing though. As Joe notes, this was just how you most easily encode binary data in JSON. We did discuss that the encoding has a minor benefit to “over the shoulder reader” obscurity, but that wasn’t the goal.
- azaras 5y agoIt is true, in configmap objects you can not store binary data.
- aequitas 5y agoYou can always add 3rot13 on top of it for extra security.
- kristaps 5y agoSounds like the marketing department participated in writing the docs this time.
- gogetmb 5y agoFWIW, this site is not a corporate blog, but a community encouraging current and aspiring sysadmins to learn in public. The author is not an official spokesperson and is very new. Also, I should have caught this point before hitting publish, so it's my bad. And if it's not obvious: Red Hat wrote enough of Kubernetes to know better than to base64 anything of value.