fix(security): avoid logging OpenBao unseal keys in argv - #2729
Draft
devantler wants to merge 2 commits into
Draft
fix(security): avoid logging OpenBao unseal keys in argv#2729devantler wants to merge 2 commits into
devantler wants to merge 2 commits into
Conversation
Contributor
Author
|
Contributor
Author
|
@cursor review |
Contributor
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_095cd5db-89a8-4ab5-81ba-ead2b8914ce6) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
process_execevents to stdout, and OpenBao initialization/unseal paths pass the unseal key on the command line, which makes the key persistently discoverable via the existing Alloy→Loki pipeline.Description
bao operator unseal "$UNSEAL_KEY"with piping the key tobao operator unsealvia stdin usingprintf '%s\n' "$UNSEAL_KEY" | bao operator unsealto avoid placing secrets inargvinpostStarthooks and jobs.k8s/bases/infrastructure/controllers/openbao/helm-release.yamlandk8s/bases/infrastructure/vault-config/job.yaml.fix(security): avoid logging OpenBao unseal keys in argv(two-file change, 3 insertions, 3 deletions).Testing
rgpattern check to ensure no remainingbao operator unsealargv usages matching the previous patterns and the check succeeded.python3 scripts/validate-embedded-json.pyandpython3 scripts/validate-naming.py, all of which succeeded in this environment.git diff --checkwith no whitespace/errors reported, and attemptedkubectl kustomize/ksail workload validatecould not be executed in this environment becausekubectlandksailare not installed (manualksail/kubectl kustomizevalidation is recommended before merge).Codex Task