bottlerocket-os / bottlerocket-os/bottlerocket-test-system
support more secure secrets
- Dominant language
- Rust
- Stars
- 18
- Forks
- 27
- PR merge metrics
- No merged PRs in 30d
Description
Right now we have the ability to use plain Kubernetes secrets in our test and resource agents. This is not sufficiently secure for long-lived testsys clusters. We need a stronger secret storage option. For example, we could store them in SSM and pull them from the bottlerocket agents. Or we could do something else that is more Kubernetes-native.
Contributor guide
Research direction
No files, tests, or entry points are named. Start by locating how plain Kubernetes secrets are used by the test and resource agents, then assess the SSM and Kubernetes-native options for Bottlerocket agents. Done means a stronger secret-storage approach is selected, implemented, and verified for long-lived testsys clusters.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, kubernetes, rust
- Domain
- infrastructure, security, testing-qa
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100