-
Notifications
You must be signed in to change notification settings - Fork 49
Fix k8s Secret manifest with plaintext CHANGE_ME placeholders #560
Copy link
Copy link
Open
Labels
GrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardThird CampaignCampaign: Third CampaignCampaign: Third CampaigndevopsIssues related to infrastructure, CI/CD, and deploymentIssues related to infrastructure, CI/CD, and deploymentmediumModerate tasksModerate taskssecurityIssues related to application security and auditsIssues related to application security and audits
Description
Activity
Metadata
Metadata
Assignees
Labels
GrantFox OSSIssue tracked in GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardIssue may be eligible for a GrantFox rewardThird CampaignCampaign: Third CampaignCampaign: Third CampaigndevopsIssues related to infrastructure, CI/CD, and deploymentIssues related to infrastructure, CI/CD, and deploymentmediumModerate tasksModerate taskssecurityIssues related to application security and auditsIssues related to application security and audits
What
backend-secret.yamlis committed to git withstringDatacontaining CHANGE_ME placeholders for DATABASE_URL, JWT_SECRET, STELLAR_SECRET_KEY. Anyone who deploys without overriding runs with known credentials.Why
Known credentials in a payroll system is a critical security issue. The secret should use an external secret manager.
Scope
In scope: Use Sealed Secrets or External Secrets Operator, remove plaintext from git, document safe-apply workflow
Out of scope: Vault setup
Acceptance Criteria
Technical Context
k8s/base/backend-secret.yaml— plaintext placeholdersinfrastructure/terraform/modules/secrets/— AWS Secrets Manager