Page MenuHomePhabricator

[terraform] Avoid including Terraform *.tfstate.backup in keyserver docker images
ClosedPublic

Authored by will on Jul 22 2024, 5:55 PM.
Tags
None
Referenced Files
F3000374: D12849.diff
Fri, Oct 18, 1:48 AM
Unknown Object (File)
Sat, Oct 12, 12:37 AM
Unknown Object (File)
Sat, Sep 28, 12:37 PM
Unknown Object (File)
Wed, Sep 25, 5:44 PM
Unknown Object (File)
Wed, Sep 18, 7:05 PM
Unknown Object (File)
Sep 10 2024, 7:53 PM
Unknown Object (File)
Sep 9 2024, 9:51 PM
Unknown Object (File)
Sep 9 2024, 5:45 PM
Subscribers

Details

Summary

Files like terraform.tfstate.backup expose secrets in the keyserver image and should be

Test Plan

Tested by building the docker image, opening the build with docker run -it docker_image bash and
searching for my password cd .. && (grep -R password_string . | grep -v node_modules) as we did in https://phab.comm.dev/D12823

Diff Detail

Repository
rCOMM Comm
Branch
add_to_dockerignore
Lint
No Lint Coverage
Unit
No Test Coverage