Explore using onetimesecret.com (or a self-hosted version) to pass secrets to user-data #11

Open
opened 2026-01-03 19:48:28 +00:00 by tom · 3 comments
Owner

Doing this would allow passing a token that explodes on use - so it would only be available during provisioning.

Doing this would allow passing a token that explodes on use - so it would only be available during provisioning.
Owner

Interesting idea - but that does then make re-provisioning something you can't do in a hurry, because the secrets-would have to be preloaded .. presumably by hand?

Interesting idea - but that does then make re-provisioning something you can't do in a hurry, because the secrets-would have to be preloaded .. presumably by hand?
Owner

I suppose one could store a batch of a longer-lived credentials encrypted with one single-use key, to be retrieved this way? Maybe combine with https://github.com/getsops/sops ?

I suppose one could store a batch of a longer-lived credentials encrypted with one single-use key, to be retrieved this way? Maybe combine with https://github.com/getsops/sops ?
Author
Owner

I've not used sops, though it's got a huge readme. This may be good or bad :)

Thinking about it more, perhaps the best way is some kind of bootstrap cred that gives access to whatever. The cred itself could be longer-lived too - it would just be access that's one time. Once the box has built it should in theory already be trusted to get secrets via some other mechanism?

I've not used sops, though it's got a huge readme. This may be good or bad :) Thinking about it more, perhaps the best way is some kind of bootstrap cred that gives access to whatever. The cred _itself_ could be longer-lived too - it would just be access that's one time. Once the box has _built_ it should in theory already be trusted to get secrets via some other mechanism?
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
spoons.technology/core-infra#11
No description provided.