NVIDIA / NVIDIA/nvcf

Support injecting NVCF secrets as environment variables

Open
#68 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

roadmap
Dominant language
Go
Stars
218
Forks
72
Avg merge
1d 12h
Merged PRs (30d)
427

Description

Description

Some prebuilt containers can consume secrets only through environment variables and cannot be changed to read NVCF secret files. Add an opt-in delivery mode that exposes configured NVCF secrets as environment variables to applicable workload containers.

Environment variables cannot be updated in a running process. This mode must make clear that rotated values become available only after the workload is restarted or redeployed.

Definition of Done

  • A function deployment can select environment-variable delivery for configured secrets.
  • Secret delivery works without requiring changes to the target container image.
  • The rotation and restart behavior of environment-delivered secrets is documented.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files, tests, or entry points are identified in the issue. Start by locating the function-deployment secret-delivery path and the documentation for configured NVCF secrets. Done means deployments can opt into environment-variable delivery without image changes, and the documentation explains that rotated values require a workload restart or redeployment.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
cloud, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.