15 ms·
It's not about the API key. It's about the container registry credentials. Which you would expect to be able to only interact with the container registry. This
by drogus 3y ago
It's not about the API key. It's about the container registry credentials. Which you would expect to be able to only interact with the container registry. This is not the case. If you go to the container registry and click to download credentials you will get JSON like:
{"auths":{"registry.digitalocean.com":{"auth":"<base64-encoded-credentials>"}}}
If you decode the base64 encoded credentials it will be a string like "<token>:<token>" with either a read only or read/write token to all of the resources on DO.
- dijksterhuis 3y ago> It's not about the API key. It's about the container registry credentials. Which you would expect to be able to only interact with the container registry. think my reply shortness maybe has you misunderstanding me? The fact that an API token can only have read/write project wide basically results in everything you said. No RBAC on services. No RBAC on specific API actions. Anyone with read+write can do/nuke everything. That’s why I’m migrating $COMPANY off to AWS as fast as I humanly can by myself.
- drogus 3y agoOk, I see what you mean. Still, even knowing that general access tokens are all or nothing it was surprising that exactly the same thing was used for containers. Like, if you generate a separate credentials for containers it strongly suggests there are for containers only.
- dijksterhuis 3y agoYeah I use doctl, which has a big note on the docs saying > you can simulate what `doctl registry login` does by using an API token string as the username and password when calling `docker login` https://docs.digitalocean.com/products/container-registry/how-to/use-registry-docker-kubernetes/ https://docs.digitalocean.com/products/container-registry/ho...