EGI-Federation / fedcloud-catchall-operations

Operation of fedcloud integration components for selected providers
MIT License
5 stars 40 forks source link

Review how secrets are handled #341

Open enolfc opened 4 months ago

enolfc commented 4 months ago

Short Description of the issue

We have secrets in several places in this code and they are treated in different ways (via a file, via env variables, in GitHub Actions secrets, ...), we should review how these are managed and move to as simple and secure way as possible.

gwarf commented 4 months ago

For the record: recently Bitwarden started to provide a service meant to manage this kind of secrets: https://bitwarden.com/products/secrets-manager/.

brucellino commented 4 months ago

Seems like secrets.egi.eu would be the obvious choice?