3 ms·
Chef supports encrypted data-buckets where you decrypt only on the server. Puppet supports hiera data with encryption as well (via plugins). There's no reason a
by druiid 12y ago
Chef supports encrypted data-buckets where you decrypt only on the server. Puppet supports hiera data with encryption as well (via plugins). There's no reason anyone should be storing password information in source, especially API keys which I'm guessing this was (S3 information more than likely?). I think about the extent of private information I'd be okay with storing in source is DB user/pass information because that will generally require compromising the machine more generally first and by that point they already had access to your DB even if the password/username wasn't stored in source.
Essentially this will serve as a wake-up call to the Bitly guys and hopefully they'll take some steps to deploy this stuff via CM or similar in the future.
- thefreeman 12y agoI read it a bit differently. I don't think they store their credentials directly in their source code repository. I think they are saying they have a separate repository specifically for credentials. It seems like a bit of a strange way to manage sensitive information, but not really any worse then a lot of other things I've seen.