Stop shipping the shared credential in this repo

Fixkamo-internal
Shipped
August 11, 2026 at 3:50 AM UTC
Author
kamo
Commit
800929d

The object-storage key sat in k8s/configmap.yaml, which kubectl will hand to anyone who can read the namespace, and the same string was hardcoded as the SSH password in three connection helpers — so cluster login was in the repo too. MINIO_SECRET_KEY now comes from the minio-app-credentials secret via envFrom, wired and verified against a running pod before the ConfigMap key was removed. The SSH helpers take KAMO_SSH_PASSWORD from the environment and refuse to run without it. The HIPAA audit corpus quoted the literal as evidence in eight places. The findings are unchanged; only the credential is redacted, since a document describing the leak should not be a copy of it.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing