sphericth0r@kbin.socialtoSelfhosted@lemmy.world•Disclosure of sensitive credentials and configuration in containerized deployments - ownCloud
1·
11 months agoThat’s just as insecure lol, env vars are far better
That’s just as insecure lol, env vars are far better
But the same could be said for almost anything, for instance a car’s engine is non-theoretical but could be otherwise done with a horse instead. I will still prefer the more advanced technology, but of course you do you
And who the f wants recurring payment reminders during gameplay…
It’s probably best to look at what the devops industry is embracing, environment variables are as secure as any of the alternatives but poor implementations will always introduce attack vectors. Secret management stores require you to authenticate, which requires you to store the credential for it somewhere - no matter what there’s no way to secure an insecure implementation of secrets access