4 ms·
The Profiles idea is the interesting part. Injection at creation is the easy half; the hard half is revocation mid-session. If a credential in a profile rotates
by bobbylarson 2mo ago
The Profiles idea is the interesting part. Injection at creation is the easy half; the hard half is revocation mid-session. If a credential in a profile rotates or gets pulled while a box is up for days, does the running VM keep the old value until restart? For long horizon agents that window is where the risk actually lives.
- bwm 2mo agoHi! OAuth token refresh is handled within the profile, and will automatically get picked up by agents using it. If you actually want to pull or rotate a credential, you can do that too and re-inject. The pattern that's increasingly common is having a pilot or orchestrator agent sitting on top of the fleet that manages this.
- bobbylarson 2mo agoThe profile-plus-orchestrator pattern is a clean answer, and re-inject existing at all puts you ahead of most setups I have seen. The remaining edge: a process that read the credential at boot still holds the old value in memory after a pull. Is re-inject a workload restart, or does something force consumers to re-read? That is the part I have never seen solved cleanly without short TTLs.