# The keys toolshed encrypts stored connection credentials with. # # Connections hold access to a customer's git server, registry and cloud. # Those are not toolshed's secrets to lose, so they are encrypted with a key # the database never contains — a dump of PostgreSQL must not hand over # somebody's infrastructure. # # Format is a comma-separated list of "id:base64key", most recent first. More # than one so rotation is not a flag day: values written with an older key # keep decrypting while new ones use the new key. # # # generate a key # kubectl -n toolshed exec deploy/toolshed-api -- /usr/local/bin/keygen # session keys, not this # # Generate a 32-byte key any way you like; openssl is the shortest: # # NEW=$(openssl rand -base64 32) # kubectl -n vault exec -i vault-0 -- sh -lc " # vault login >/dev/null && # vault kv put secret/toolshed/encryption keys='k1:$NEW'" # # To rotate later, prepend a new key and keep the old one until nothing needs # it: keys='k2:,k1:'. Removing a key that still encrypts something # makes those credentials unreadable, and toolshed will say so by name rather # than reporting corruption. apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: toolshed-encryption namespace: toolshed spec: refreshInterval: 1h secretStoreRef: name: vault-backend kind: ClusterSecretStore target: name: toolshed-encryption creationPolicy: Owner data: - secretKey: keys remoteRef: key: toolshed/encryption property: keys