5 ms·
do you have any examples of more secure ways of injecting secrets?
by 89vision 3y ago
do you have any examples of more secure ways of injecting secrets?
- dharmab 3y agoCheck out the Secrets Operator for Kubernetes. Injects your secrets from a secrets store as a file mounted into your container.
- marwis 3y agoAnd how is /var/run/secrets any more secure than env? I guess you avoid the risk of accidentally logging secrets with other env variables but otherwise it seems to be just as secure/insecure.
- deleted 3y ago[deleted]
- dharmab 3y agoThe secrets aren't in a shared location. They're stored in an ephemeral volume specific to each container which other processes cannot access.
- marwis 3y agoIf someone has enough privileges to access /proc/*/environ of another process (i.e. root or the same user or process or child process) then they should be easily able to reach inside the container, no?
- lmm 3y agoOther processes running as the same user can be blocked from reading /var/run/secrets via the likes of SELinux/AppArmor whereas they can't be blocked from reading /proc/environ. It's a pretty fine distinction and I don't know how many people actually bother doing SELinux etc. in practice, but theoretically it's marginally better.
- marwis 3y agoAppArmor can restrict /proc, see example from docker: https://github.com/moby/moby/blob/master/contrib/apparmor/template.go#L41 https://github.com/moby/moby/blob/master/contrib/apparmor/te...
- 89vision 3y agohow does the application pick it up? We use the built in secrets that are injected into the container as env vars and then the application picks it up that way. Not trying to sound combative, just looking for better ways to do things.
- jameshart 3y agoRead the file on startup. Bonus: you can watch the file for changes. Which means your app can pick up rotated secrets without a process restart, whereas if you inject secrets via the environment they're fixed for process lifetime.