- Ya
- 11 Agosti 2026, 03:50 UTC
- Mwandishi
- kamo
- Ahadi ya
- 800929d
The object-storage key sat in k8s/configmap.yaml, which kubectl will hand to anyone who can read the namespace, and the same string was hardcoded as the SSH password in three connection helpers — so cluster login was in the repo too. MINIO_SECRET_KEY now comes from the minio-app-credentials secret via envFrom, wired and verified against a running pod before the ConfigMap key was removed. The SSH helpers take KAMO_SSH_PASSWORD from the environment and refuse to run without it. The HIPAA audit corpus quoted the literal as evidence in eight places. The findings are unchanged; only the credential is redacted, since a document describing the leak should not be a copy of it.