bitnami / bitnami/sealed-secrets
Sealing certificate should be signed by API server - and verified by kubeseal
Open
backlog
enhancement
- Dominant language
- Go
- Stars
- 9.3k
- Forks
- 776
- Avg merge
- 1d 13h
- Merged PRs (30d)
- 30
Description
We should use the certificates.k8s.io API to get the k8s server to sign the sealing certificate. This would allow the client to verify it has been given a valid cert and prevent potential mitm attacks.
Contributor guide
Assessment
This issue has not been assessed yet.