cloud-gov / cg-atlas

Repository hosting issues and artifacts related to operations of the cloud.gov platform
Creative Commons Zero v1.0 Universal
3 stars 1 forks source link

[research: 3d] Figure out how to improve platform secrets management #95

Closed afeld closed 7 years ago

afeld commented 8 years ago

In order to know how to reduce friction and risk from manual secrets-handling, we want to spend up to 3 days discussing and prototyping options for better secrets management.

Acceptance Criteria


We, as a team, feel that there's a lot of room for how we manage secrets for the platform. The main areas are:

Our current practice includes:

For both BOSH and Concourse, we need to figure out:

@LinuxBozo Anything I missed?

@mogul Ideas about the best way to proceed? Do we do a kickoff meeting internally? Do we reach out to teams outside of 18F via various channels and see who's interested in having a little summit (or something) around this?

Relevant links

rogeruiz commented 8 years ago

Related to the work on #33

afeld commented 8 years ago
mogul commented 8 years ago

From #general in the CF slack... image

datn commented 7 years ago

I've begun looking into Vault and will try to generate some well groomed issues around steps that need taking about secrets management.

jmcarp commented 7 years ago

If we decide to mess with vault, I started https://github.com/jmcarp/cg-deploy-vault a while back.

datn commented 7 years ago

Thanks @jmcarp !

datn commented 7 years ago

Picking this back up, I am now running Vault locally to learn about it and see whether it's feasible to address the concern about unsealing in an automated environment that Josh brought up (which is touched on here and here.

jmcarp commented 7 years ago

WIP Proposal:

Note: this proposal only touches bosh secrets. I'm thinking we might want to defer changes to concourse secrets until concourse adds native support for vault and other backends.

mogul commented 7 years ago

To be closed once an implementation story is documented.

rogeruiz commented 7 years ago

I'll add the implementation story today

rogeruiz commented 7 years ago

Closed by 18F/cg-product#657