3025 shaares
Summary
- Having a secrets manager that hands out secrets to services and clients is useful, because it allows you to prevent materialization of secrets.
- One of the primary features of clouds (private and public) would be that the control-plane of the cloud can attest identity of instances, and would allow you to solve authentication trivially. Sadly, Openstack and all Openstack derives private and public clouds seem to not implement that (and thus offer no IAM to services based on control-plane trust).
- For those where the cloud control-plane does not offer IAM, Hashivault can help out a lot.
- Some applications have the ability to have multiple passwords per identity, to allow easier password rotation.
- The value of that feature is greatly diminished by a lack of observability. Any control is only complete if it can be verified to work. We need to be able to see if old deprecated passwords are unused in order to safely deprovision them.
- Even without multiple passwords, we can always leverage a secrets manager and some relatively simple external driver to rotate accounts instead.
- This is complicated by the fact that many applications bind authorizations (access permissions) to identities (usernames).
- We can use roles to work around that, and assign authorizations to these roles, then have the identity inherit from the role.
- Implementing either account rotation or password rotation still requires additional work: an external driver, safeguards, monitoring and alerting, plus an update of the documentation. In neither case you will be done by simply turning on a feature.