3 ms·
> ArgoCD not password protecting the Redis they deploy is amateur hour.. You can meme it with SPIFFE/SPIRE. > Secrets objects, which aren't really secret beca
by tjwjfasdflajsdf 2y ago
> ArgoCD not password protecting the Redis they deploy is amateur hour..
You can meme it with SPIFFE/SPIRE.
> Secrets objects, which aren't really secret because there's no encryption, but that's another topic
This isn't universally true anymore, at least with AWS EKS.
- sofixa 2y ago> This isn't universally true anymore, at least with AWS EKS. The underlying etcd being encrypted at rest doesn't really change the fact that anything with access to the running etcd has full access to all secrets (okay, there are ACLs, but they're quite complex).