4 ms·
> Establishing AWS identity outside of AWS is a headache, and often comes with a chicken-and-egg problem of needing to possess a secret to show you are allowed
by maayank 2y ago
> Establishing AWS identity outside of AWS is a headache, and often comes with a chicken-and-egg problem of needing to possess a secret to show you are allowed to get a secret.
> For most stuff here, we can rely on the fact that every connection over Tailscale is encrypted and authenticated to an identity
Mm, okay, but you still have the chicken and egg problem of distributing the creds to join your tailnet.
Isn’t it not that different than distributing aws creds to access secrets manager?
- captn3m0 2y agoYou can use Instance credentials within AWS to avoid chicken and egg. Your instance short-lived creds are strongly tied to the instance identity itself.
- maayank 2y agoYes, that’s what I do. The way I read the tailscale post it suggested a magical way to circumvent this credentials bootstrapping dance