Files

44 lines
1.5 KiB
YAML

# The keys toolshed encrypts stored connection credentials with.
#
# Connections hold access to a customer's git server, registry and cloud.
# Those are not toolshed's secrets to lose, so they are encrypted with a key
# the database never contains — a dump of PostgreSQL must not hand over
# somebody's infrastructure.
#
# Format is a comma-separated list of "id:base64key", most recent first. More
# than one so rotation is not a flag day: values written with an older key
# keep decrypting while new ones use the new key.
#
# # generate a key
# kubectl -n toolshed exec deploy/toolshed-api -- /usr/local/bin/keygen # session keys, not this
#
# Generate a 32-byte key any way you like; openssl is the shortest:
#
# NEW=$(openssl rand -base64 32)
# kubectl -n vault exec -i vault-0 -- sh -lc "
# vault login <root-token> >/dev/null &&
# vault kv put secret/toolshed/encryption keys='k1:$NEW'"
#
# To rotate later, prepend a new key and keep the old one until nothing needs
# it: keys='k2:<new>,k1:<old>'. Removing a key that still encrypts something
# makes those credentials unreadable, and toolshed will say so by name rather
# than reporting corruption.
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: toolshed-encryption
namespace: toolshed
spec:
refreshInterval: 1h
secretStoreRef:
name: vault-backend
kind: ClusterSecretStore
target:
name: toolshed-encryption
creationPolicy: Owner
data:
- secretKey: keys
remoteRef:
key: toolshed/encryption
property: keys