Chef Vault does address one of the earlier concerns you raised about the scalability of mass-distributing keys to use for decrypting data bags. Instead it uses the client keys on the individual nodes to encrypt separate copies of your data bag item (one for each host that’s allowed to access it). That way you don’t have to worry (much) about key management, and access to the data is not universal (like it is with normal encrypted data bags, which were invented mainly as a way to not store sensitive data in source control). -- Eric On November 17, 2014 at 3:33:53 PM, Eric Herot ( "> ) wrote:
|
Archive powered by MHonArc 2.6.16.