Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Secret Management for Sub-Clusters #192

Open
lb4368 opened this issue Jul 2, 2021 · 0 comments
Open

Secret Management for Sub-Clusters #192

lb4368 opened this issue Jul 2, 2021 · 0 comments
Labels
2-Manifests Relates to manifest/document set related issues enhancement New feature or request priority/low Items that are considered non-critical for functionality, such as quality of life improvements
Milestone

Comments

@lb4368
Copy link

lb4368 commented Jul 2, 2021

Problem description
Currently all encrypted secrets such as CAs, ssh keys, Dex client secrets, etc. are managed as part of the management cluster. As sub-clusters are added to multi-tenant sites, there needs to be a mechanism to manage secrets specific to individual sub-clusters.

Proposed change

  1. Provide a mechanism to generate and encrypt secrets specific to an individual sub-cluster.
  2. Provide a mechanism to provide external secrets specific to an individual sub-cluster.
  3. All secrets must be encrypted at rest and encryption key for sub-cluster may be the same or different from one used in management cluster.
@lb4368 lb4368 added enhancement New feature or request triage 2-Manifests Relates to manifest/document set related issues labels Jul 2, 2021
@jezogwza jezogwza removed the triage label Jul 14, 2021
@jezogwza jezogwza added the priority/low Items that are considered non-critical for functionality, such as quality of life improvements label Jul 14, 2021
@jezogwza jezogwza added this to the Future milestone Jul 14, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
2-Manifests Relates to manifest/document set related issues enhancement New feature or request priority/low Items that are considered non-critical for functionality, such as quality of life improvements
Projects
None yet
Development

No branches or pull requests

2 participants