[chef] Re: Re: Encrypted Data Bag Item Changes in Chef 11


Chronological Thread 
  • From: Daniel DeLeo < >
  • To:
  • Subject: [chef] Re: Re: Encrypted Data Bag Item Changes in Chef 11
  • Date: Thu, 22 Nov 2012 06:03:25 -0800



On Tuesday, November 20, 2012 at 2:58 PM, steve . wrote:

I took a stab at writing a knife plugin that might help automate the migration process (subclassing Chef::Knife::DataBagFromFile).  The plugin backs up your Chef server's data bag items, decrypts them, then re-encrypts them and re-uploads them.  Well, actually, it *would* re-upload them but since this all just got announced I thought it'd be safer to leave that functionality commented out.  It does save JSON copies of "before," "during" and "after" so you can see what it would do.

Here's the code:


If someone (who already has the infrastructure in place) wants to give it a try, I'd love to hear the results. We're going to have to upgrade a lot of folks internally when Chef 11 comes around and we'd like to be prepared...

Thanks for sharing this. 

-- 
Daniel DeLeo
 




Archive powered by MHonArc 2.6.16.

§