4 ms·
Secrets Don't Belong in Config
- burnt-resistor 3mo agoUse a template-based configuration management system to pull in secrets from a secrets management system (passwords/credentials/PKI management). It's an antipattern to add even more complexity by bolting on configuration or secrets management as part of nix, systemd, or anything else that's OS- or distro-specific. Package managers, and OSes need to offer sane defaults but then have sensible boundaries and allow configuration responsibility to be delegated to users and/or configuration management.
- eviks 3mo agoHow would that help if the result of the template is the same single config file that doesn't separate concerns?
- burnt-resistor 3mo agoFacts sources, logic, and secrets are typically best using logic-less templates. Good configuration management systems are sufficiently understandable, flexible, and maintainable. If a file is static, then most configuration management systems allow dropping in such too without templates. What specific question or concern do you have?
- eqvinox 3mo agoWho other than nixOS has this problem? Feels like a nixOS thing to me, which I'm not going to complicate my applications for. All the orchestration tools have something like a vault, don't they? Happy to be shown wrong though.
- austinshea 3mo agojust explain your pattern. what you are saying means you have a leaky chain of custody and are fine with that, but you can show why i'm wrong.