fleetdm / fleet

Open-source platform for IT, security, and infrastructure teams. (Linux, macOS, Chrome, Windows, cloud, data center)
https://fleetdm.com
Other
3.16k stars 433 forks source link

Use secrets in scripts or profiles #23238

Open noahtalerman opened 1 month ago

noahtalerman commented 1 month ago

Goal

User story
As an IT admin,
I want to make sure that my GitHub or GitLab secrets (e.g. API tokens or software license keys) used in scripts and profiles are not displayed when those are viewed or downloaded
so that I can be sure that secrets are hidden until they get on the hosts.

Key result

Deliver customer promises and prioritized requests

Original requests

Context

Changes

Product

Engineering

ℹ️  Please read this issue carefully and understand it. Pay special attention to UI wireframes, especially "dev notes".

QA

Risk assessment

Manual testing steps

  1. Step 1
  2. Step 2
  3. Step 3

Testing notes

Confirmation

  1. [ ] Engineer (@____): Added comment to user story confirming successful completion of QA.
  2. [ ] QA (@____): Added comment to user story confirming successful completion of QA.
noahtalerman commented 3 days ago

FYI @marko-lisica, now that the next estimation is scheduled for next week (when George is back), I assigned this story and the other story (#23344) in "Ready to spec" back to George.

I think we assigned @lukeheath to these stories when we were still planning on having estimation today.