kubernetes-sigs/cluster-api

Service Account Private Key Rotation

Open

#7 456 ouverte le 25 oct. 2022

Voir sur GitHub
 (6 commentaires) (2 réactions) (0 assignés)Go (1 532 forks)auto 404
help wantedkind/featurekind/proposallifecycle/frozenpriority/backlogtriage/accepted

Métriques du dépôt

Stars
 (4 267 stars)
Métriques de merge PR
 (Métriques PR en attente)

Description

User Story

As a developer I would like to setup a rotation mechanism service account private keys for security. Rotating RSA-2048 keys is essential if I use the SA key to sign projected service-bound tokens.

Detailed Description

I would like CAPI to:

  1. Create the new key pair.
  2. Allow the user to create a mechanism in which it can intercept the newly generated key-pair so it can update internal systems before it is rolled out.
  3. Run machine repave with no downtime. (eg publishing public key first and then private key through 2 machine repaves).

Anything else you would like to add:

N/A

/kind feature

Guide contributeur