bottlerocket-os / bottlerocket-os/bottlerocket-test-system

support more secure secrets

Open
#414 0 comments 0 reactions 0 assignees View on GitHub
bottlerocket priority/mid
Dominant language
Rust
Stars
18
Forks
27
PR merge metrics
No merged PRs in 30d

Description

Right now we have the ability to use plain Kubernetes secrets in our test and resource agents. This is not sufficiently secure for long-lived testsys clusters. We need a stronger secret storage option. For example, we could store them in SSM and pull them from the bottlerocket agents. Or we could do something else that is more Kubernetes-native.

Contributor guide

Open the contributing guide

Research direction

No files, tests, or entry points are named. Start by locating how plain Kubernetes secrets are used by the test and resource agents, then assess the SSM and Kubernetes-native options for Bottlerocket agents. Done means a stronger secret-storage approach is selected, implemented, and verified for long-lived testsys clusters.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, kubernetes, rust
Domain
infrastructure, security, testing-qa
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.