kubernetes-sigs/cluster-api

Service Account Private Key Rotation

Offen

#7.456 geöffnet am 25.10.2022

 (6 Kommentare) (2 Reaktionen) (0 zugewiesene Personen)Go (1.532 Forks)auto 404
help wantedkind/featurekind/proposallifecycle/frozenpriority/backlogtriage/accepted

Repository-Metriken

Stars
 (4.267 Sterne)
PR-Merge-Metriken
 (PR-Metriken ausstehend)

Beschreibung

User Story

As a developer I would like to setup a rotation mechanism service account private keys for security. Rotating RSA-2048 keys is essential if I use the SA key to sign projected service-bound tokens.

Detailed Description

I would like CAPI to:

  1. Create the new key pair.
  2. Allow the user to create a mechanism in which it can intercept the newly generated key-pair so it can update internal systems before it is rolled out.
  3. Run machine repave with no downtime. (eg publishing public key first and then private key through 2 machine repaves).

Anything else you would like to add:

N/A

/kind feature

Contributor Guide