Uploaded image for project: 'AI Platform Core Components'
  1. AI Platform Core Components
  2. AIPCC-8902

Replace BOT_PAT with podman secrets

    • Icon: Epic Epic
    • Resolution: Unresolved
    • Icon: Minor Minor
    • None
    • None
    • Development Platform
    • None
    • Podman secrets
    • False
    • Hide

      None

      Show
      None
    • False
    • To Do
    • 0% To Do, 100% In Progress, 0% Done
    • DP Sprint 24
    • Low

      The goal is at some point to completely move out from using the BOT_PAT Gitlab token for authentication. Currently, there is high security risk that a compromise of a Gitlab worker might lead to unauthorized access to the registries and so on, by using BOT_PAT (which is visible to any worker). As a first step towards securing the authentication process we aim to replace the builder image containers' access to BOT_PAT (passed as an environment variable to the containers) with Podman secrets. Podman secrets will prevent BOT_PAT from leaking into the CI logs (for now). When BOT_PAT is replaced by a more secure alternative in the future, the new solution should be compatible with the podman secrets. 

              iangelak@redhat.com Ioannis Angelakopoulos
              iangelak@redhat.com Ioannis Angelakopoulos
              Antonio's Team
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: