weixin_39563823
2020-12-27 01:18Vault
This adds support for secrets stored in Hashicorp Vault. What is here should be heavily documented in the diff itself, so I'll defer to that rather than writing more here in the PR body. This is all rather much, so please do tear it apart and let me know if anything is confusing, misleading, dangerous, insecure, etc.
Open questions:
- monitoring of fetcher daemon: The daemon will run as an appcommon::daemon which means we'll get log shipping and QA checks for free. There's not any facility for alerting on sudden failure down the line though.
Future work:
- HVAC integration. The integration should take the vault_token from this stuff and allow full in-app access to vault's more interesting features (like the transit backend). All with diagnostics instrumentation, of course!
- Database credentials: The database helpers should get integration with the Vault stuff so that apps can automatically fetch rotating DB credentials.
该提问来源于开源项目:reddit/baseplate.py
- 点赞
- 回答
- 收藏
- 复制链接分享
6条回答
为你推荐
- 新连接失败时,使用数据库/ SQL库并从保管库获取密码
- it技术
- 互联网问答
- IT行业问题
- 计算机技术
- 编程语言问答
- 2个回答
- 解密后的反向代理服务文件
- http
- fileserver
- proxy
- 1个回答
- 使用Vault API软件包的身份验证方法
- it技术
- 互联网问答
- IT行业问题
- 计算机技术
- 编程语言问答
- 1个回答
- 未检测到保管库令牌助手?
- devops
- 1个回答
- 单个提交按钮上有两个_POST
- mysql
- post
- php
- 1个回答
换一换