Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adding the generation of keys and certificates for the storage service #496

Merged
merged 3 commits into from
Sep 16, 2024

Conversation

slashben
Copy link
Contributor

@slashben slashben commented Sep 4, 2024

Overview

This is part of solving kubescape/storage#117
and requires kubescape/storage#145 to be merged and released

In this PR we are setting up storage with:

  1. CA Certificate
  2. Signed server certificate and key
  3. API server to require the above CA Certificate
  4. Storage to require API server client certificate

Copy link

gitguardian bot commented Sep 4, 2024

⚠️ GitGuardian has uncovered 8 secrets following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secrets in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
13676262 Triggered RSA Private Key 87b51f9 charts/kubescape-operator/tests/snapshot/snapshot_test.yaml.snap View secret
13676262 Triggered RSA Private Key 2575fd8 charts/kubescape-operator/tests/snapshot/snapshot_test.yaml.snap View secret
13676263 Triggered RSA Private Key 87b51f9 charts/kubescape-operator/tests/snapshot/snapshot_test.yaml.snap View secret
13676263 Triggered RSA Private Key 2575fd8 charts/kubescape-operator/tests/snapshot/snapshot_test.yaml.snap View secret
13676264 Triggered RSA Private Key 87b51f9 charts/kubescape-operator/tests/snapshot/snapshot_test.yaml.snap View secret
13676264 Triggered RSA Private Key 2575fd8 charts/kubescape-operator/tests/snapshot/snapshot_test.yaml.snap View secret
13676265 Triggered RSA Private Key 87b51f9 charts/kubescape-operator/tests/snapshot/snapshot_test.yaml.snap View secret
13676265 Triggered RSA Private Key 2575fd8 charts/kubescape-operator/tests/snapshot/snapshot_test.yaml.snap View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secrets safely. Learn here the best practices.
  3. Revoke and rotate these secrets.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

@matthyx matthyx merged commit 893ff19 into main Sep 16, 2024
7 checks passed
@matthyx matthyx deleted the feature/setting-up-storage-mtls-securely branch September 16, 2024 12:29
matthyx added a commit that referenced this pull request Sep 16, 2024
…rage-mtls-securely"

This reverts commit 893ff19, reversing
changes made to 1699fd5.

Signed-off-by: Matthias Bertschy <[email protected]>
@matthyx matthyx restored the feature/setting-up-storage-mtls-securely branch September 19, 2024 20:22
@matthyx
Copy link
Contributor

matthyx commented Sep 19, 2024

@slashben can you reopen this PR and confirm it works? I had issues with my kind cluster validating the previous release...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants