- From: George Miranda <
>
- To: "
" <
>
- Subject: [chef] Fwd: Re: Re: AWS Security Groups
- Date: Tue, 18 Nov 2014 13:27:14 -0800
Forwarded to the list, since it appears to have been only (mistakenly) addressed to me.
---------- Forwarded message ----------
From:
Greg Zapp <
">
>Date: Mon, Nov 17, 2014 at 4:31 PM
Subject: Re: [chef] Re: Re: AWS Security Groups
To:
">
Hi Douglas,
For what it's worth I use S3 to store extra IAM role secrets. Each IAM role has access to an S3 object(or prefix) where extra secrets related to that role are stored in json files. I fetch those down in a "secrets" cookbook that then loads them into the run. Some cookbooks won't be flexible enough for this; they care too much about how the information gets into the Chef run. In those cases I'll either work around it or fork the cookbook as necessary. I try to create my own bottom level(infrastructure?) cookbooks/recipes/providers to not concern themselves with actually fetching the secrets from their source. I use a cookbook that prevents certain node attributes from being saved back to the server "blacklist-node-attrs", this is configured to not save anything under the "secrets" key however I will probably investigate using chef.run_state.
I know this doesn't have anything to do with data bags, but maybe it will give you some ideas that will help you accomplish your goals.
Cheers,
-Greg
- [chef] Re: Re: Re: Re: Re: Re: Re: Re: AWS Security Groups, (continued)
- Message not available
- Message not available
- Message not available
- [chef] Re: Re: Re: Re: Re: Re: Re: Re: AWS Security Groups, Douglas Garstang, 11/17/2014
- [chef] Re: Re: Re: Re: Re: Re: Re: Re: Re: AWS Security Groups, Eric Herot, 11/17/2014
- [chef] Re: Re: Re: Re: Re: Re: Re: Re: Re: AWS Security Groups, Fabien Delpierre, 11/17/2014
- [chef] Re: Re: Re: Re: Re: Re: Re: Re: Re: Re: AWS Security Groups, Douglas Garstang, 11/17/2014
- [chef] Re: Re: Re: Re: Re: Re: Re: Re: Re: Re: Re: AWS Security Groups, Fabien Delpierre, 11/17/2014
- [chef] Re: Re: Re: Re: Re: Re: Re: Re: Re: Re: Re: Re: AWS Security Groups, Douglas Garstang, 11/17/2014
- [chef] Re: AWS Security Groups, Eric Herot, 11/17/2014
- [chef] Re: AWS Security Groups, Eric Herot, 11/17/2014
- [chef] Re: AWS Security Groups, Douglas Garstang, 11/17/2014
- [chef] Re: Re: AWS Security Groups, George Miranda, 11/17/2014
- Message not available
- [chef] Fwd: Re: Re: AWS Security Groups, George Miranda, 11/18/2014
- [chef] Re: Fwd: Re: Re: AWS Security Groups, Peter Burkholder, 11/18/2014
- [chef] Re: Re: Fwd: Re: Re: AWS Security Groups, Greg Zapp, 11/18/2014
- [chef] Re: Re: Re: Re: Re: Re: Re: Re: AWS Security Groups, Fabien Delpierre, 11/17/2014
Archive powered by MHonArc 2.6.16.