KamoCRM

Stop shipping the shared credential in this repo

Fixkamo-internal
Shipped
11 ஆகஸ்ட், 2026 அன்று 3:50 AM UTC
Author
kamo
Commit
800929d

The object-storage key sat in k8s/configmap.yaml, which kubectl will hand to anyone who can read the namespace, and the same string was hardcoded as the SSH password in three connection helpers — so cluster login was in the repo too. MINIO_SECRET_KEY now comes from the minio-app-credentials secret via envFrom, wired and verified against a running pod before the ConfigMap key was removed. The SSH helpers take KAMO_SSH_PASSWORD from the environment and refuse to run without it. The HIPAA audit corpus quoted the literal as evidence in eight places. The findings are unchanged; only the credential is redacted, since a document describing the leak should not be a copy of it.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing