Encrypted data bags were never intended to do anything else. Anyone who uses them for anything else is just setting themselves up for future pain and problems. Anyone who recommends that anyone use them for anything else is being foolish and reckless.Encrypted databags provide protection against two kinds of access:I also disagree, especially with your assertion of what and "how many" things EDB is protecting against.I've certainly been in the situation of sharing a common Chef code-base amongst many groups where secrets needed to be siloed amongst consumers, and kept from the administrators of the source control system too. We shouldn't assume there is one operations group that is the keeper of all of the keys, because in most large organisations that isn't the case.
Archive powered by MHonArc 2.6.16.