[chef] Re: Re: secure knife use


Chronological Thread 
  • From: Tim Dunphy < >
  • To:
  • Subject: [chef] Re: Re: secure knife use
  • Date: Fri, 18 Jan 2013 07:24:12 -0500

Excellent points made. Thank you for your reply!

On Thu, Jan 17, 2013 at 10:11 PM, Daniel Condomitti < " target="_blank"> > wrote:
They would need your client certificate to do anything. That should only be on the machine you're running knife on, not in source control. If you still want ip restrictions do it with firewall rules or source filtering in something in front of chef-server (nginx, etc)
Hello list,

 Is there a way to secure my community chef server so that one may only use knife commands from specific IPs. My friend made a valid point that if anyone were able to hack my git server (unlikely but possible) they would be able to wreak havok on my infrastructure using my own chef server. Any thoughts on this?

Thanks
Tim

--
GPG me!!

gpg --keyserver pool.sks-keyservers.net --recv-keys F186197B




--
GPG me!!

gpg --keyserver pool.sks-keyservers.net --recv-keys F186197B




Archive powered by MHonArc 2.6.16.

§