Page MenuHomePhabricator

[terraform] Avoid including Terraform *.tfstate.backup in keyserver docker images
ClosedPublic

Authored by will on Jul 22 2024, 5:55 PM.
Tags
None
Referenced Files
Unknown Object (File)
Fri, Nov 1, 10:45 AM
Unknown Object (File)
Fri, Nov 1, 10:45 AM
Unknown Object (File)
Fri, Nov 1, 10:45 AM
Unknown Object (File)
Fri, Nov 1, 10:44 AM
Unknown Object (File)
Oct 20 2024, 2:08 PM
Unknown Object (File)
Oct 18 2024, 3:23 AM
Unknown Object (File)
Oct 18 2024, 1:48 AM
Unknown Object (File)
Oct 12 2024, 12:37 AM
Subscribers

Details

Summary

Files like terraform.tfstate.backup expose secrets in the keyserver image and should be

Test Plan

Tested by building the docker image, opening the build with docker run -it docker_image bash and
searching for my password cd .. && (grep -R password_string . | grep -v node_modules) as we did in https://phab.comm.dev/D12823

Diff Detail

Repository
rCOMM Comm
Lint
Lint Not Applicable
Unit
Tests Not Applicable