[Tracking Issue] Secret management at scale #156

Open
opened 2024-12-15 16:13:09 +00:00 by raito · 4 comments
Owner

Here's the list of things we need to convert to our Vault server.

  • Monitoring
  • Terraform S3 access keys for operators
  • AppRole via SPIFFE
  • OfBorg's RabbitMQ connections
  • PostgreSQL's connections for Hydra & co.
Here's the list of things we need to convert to our Vault server. - [x] Monitoring - [x] Terraform S3 access keys for operators - [ ] AppRole via SPIFFE - [x] OfBorg's RabbitMQ connections - [ ] PostgreSQL's connections for Hydra & co.
Author
Owner

OfBorg done in #162.
Next is PostgreSQL for Hydra. Terraform S3 requires a privileged sort of API to emit scoped keys which we do not have right now. With Ceph RGW, that's very feasible.

OfBorg done in https://git.lix.systems/the-distro/infra/pulls/162. Next is PostgreSQL for Hydra. Terraform S3 requires a privileged sort of API to emit scoped keys which we do not have right now. With Ceph RGW, that's very feasible.
Author
Owner

Monitoring done in a1f2c9209f and 72e2c8f93b ; thanks to @k900 !

Monitoring done in https://git.lix.systems/the-distro/infra/commit/a1f2c9209f73101276868770c595ae8a926189e3 and https://git.lix.systems/the-distro/infra/commit/72e2c8f93b06cba51c34d40a4c3d549e9895f750 ; thanks to @k900 !
Author
Owner

Daily operations roles done in 85c71e7bd0. Now we need developer experience to connect via SSO and stuff and some testing.

I will set the S3 access key secret now and write a proper shell for operators.

Daily operations roles done in 85c71e7bd04221e4fc9060819817bb9816fa677d. Now we need developer experience to connect via SSO and stuff and some testing. I will set the S3 access key secret now and write a proper shell for operators.
Author
Owner

Terraform S3 fixed in #205.

Terraform S3 fixed in #205.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: the-distro/infra#156
No description provided.