Stop shipping the shared credential in this repo

Fixkamo-internal
Ya
11 Agosti 2026, 03:50 UTC
Mwandishi
kamo
Ahadi ya
800929d

The object-storage key sat in k8s/configmap.yaml, which kubectl will hand to anyone who can read the namespace, and the same string was hardcoded as the SSH password in three connection helpers — so cluster login was in the repo too. MINIO_SECRET_KEY now comes from the minio-app-credentials secret via envFrom, wired and verified against a running pod before the ConfigMap key was removed. The SSH helpers take KAMO_SSH_PASSWORD from the environment and refuse to run without it. The HIPAA audit corpus quoted the literal as evidence in eight places. The findings are unchanged; only the credential is redacted, since a document describing the leak should not be a copy of it.

Mabadiliko yote

Je, unaona nini kuhusu usafiri?

Kila moja ya hizi updates ardhi katika nafasi yako ya kazi moja kwa moja. Kuanza bure na kuangalia kukua wiki baada ya wiki.

Kuwa Huru MileleMtazamo wa bei