robusta-dev / kubernetes-chatgpt-bot

A ChatGPT bot for Kubernetes issues.
922 stars 103 forks source link

Chat GPT token exposed #18

Open carotm opened 1 year ago

carotm commented 1 year ago

If you open slack in a browser you can easily see chat_gtp_token

token

I think it's safer to remove chat_gpt_token from the Action Params and read the token from an environment variable. Also, the environment variable can be added using the value of the chart runner.additional_env_vars value, example:

runner:
  additional_env_vars:
  - name: OPENAI_API_KEY
    value: 
arikalon1 commented 1 year ago

Thank you for reporting it @carotm Typically the data required for the callback button is sent as a part of the message, but for we need to find an alternative when the parameters include sensitive data like the chat_gpt_token

SomasekharSunkari commented 1 year ago

@arikalon1 I want to Work on this Issue

arikalon1 commented 1 year ago

Of course @SomasekharSunkari Do you have a potential solution you thought of?