See: https://github.com/opscode-cookbooks/mysql readme.md The following
attributes are randomly generated passwords handled in the
If we can see ` to be easily overridden e.g. in a role.` Why? How can i understand this attribute accesseble from any client of
chef server on every node. This is unsecure, and encrypted data bag's not help us too.
Because if we store encrypted password in data bags then after
this recipe password will be store in plaintext and acceseble
anywhere. I think that we can undefine this attributes e.g. in a next
recipe included in a run list. For example: run list of a node: 1. Load passwords. There you can use you own code or for exmaple
chef-vault
node['mysql'][''server_root_password] = "" How to make it right (clear password in this defined by mysql
cookbook attributes) ?
-- Best regards, CVision Lab System Administrator Vladmir Skubriev |
Archive powered by MHonArc 2.6.16.