4 ms·
Wait till you hear that when you generate a DO container registry key it includes a key that gives you access to all of the resources, not only the registry.
by drogus 3y ago
Wait till you hear that when you generate a DO container registry key it includes a key that gives you access to all of the resources, not only the registry.
- sergioisidoro 3y agoAre you saying you have to issue a "god" level API access token to access a single docker (private) image in the Digital Ocean container registry?
- dijksterhuis 3y agoThe permissions options on the API key are read or write for the whole project. There is basically no granularity.
- drogus 3y agoIt's not about the API key. It's about the container registry credentials. Which you would expect to be able to only interact with the container registry. This is not the case. If you go to the container registry and click to download credentials you will get JSON like: {"auths":{"registry.digitalocean.com":{"auth":"<base64-encoded-credentials>"}}} If you decode the base64 encoded credentials it will be a string like "<token>:<token>" with either a read only or read/write token to all of the resources on DO.
- dijksterhuis 3y ago> It's not about the API key. It's about the container registry credentials. Which you would expect to be able to only interact with the container registry. think my reply shortness maybe has you misunderstanding me? The fact that an API token can only have read/write project wide basically results in everything you said. No RBAC on services. No RBAC on specific API actions. Anyone with read+write can do/nuke everything. That’s why I’m migrating $COMPANY off to AWS as fast as I humanly can by myself.
- drogus 3y agoOk, I see what you mean. Still, even knowing that general access tokens are all or nothing it was surprising that exactly the same thing was used for containers. Like, if you generate a separate credentials for containers it strongly suggests there are for containers only.
- dijksterhuis 3y agoYeah I use doctl, which has a big note on the docs saying > you can simulate what `doctl registry login` does by using an API token string as the username and password when calling `docker login` https://docs.digitalocean.com/products/container-registry/how-to/use-registry-docker-kubernetes/ https://docs.digitalocean.com/products/container-registry/ho...
- drogus 3y agoYes. And when you generate the container registry token it doesn't mention any of it and it's hard to notice, cause docker auth is base64 encoded. But after you decode the credentials you get a regular DO token that you can use with the API