3 ms·
I think calling it a secret when it isn’t gave it a bad wrap. The last time I looked at the documentation it didn’t even clearly describe that it is not a secur
by gscho 5y ago
I think calling it a secret when it isn’t gave it a bad wrap. The last time I looked at the documentation it didn’t even clearly describe that it is not a secure object (that may have changed recently). Why call it a secret when it is not even close to one? I guess thing-to-store-secrets-if-you-use-rbac was too long.
- threeseed 5y agoBut it can be a secret. You can store Base64-encoded, encrypted data. And you can encode it for example using an external KMS.
- Nullabillity 5y agoIf you don't use RBAC (or some other ACL mechanism) then it's already game over, everyone with access to your cluster already has full root access.
- deleted 5y ago[deleted]