runner-controller: registration token in cloud-init user-data #467

Öppen
öppnade 2026-09-08 23:04:27 +00:00 av supernaut · 0 kommentarer
Ägare

roles/runner-controller/files/runner-userdata.yaml.tmpl embeds the ephemeral runner registration token in plaintext user-data. It is readable through the OpenStack metadata service and the console log by anyone with project API access.

The token is single-use and short-lived. Either record this as an accepted risk in the runbook, or have the runner fetch the token out of band on first boot (for example from the controller over the private network with the instance id as the credential). Decide and document.

`roles/runner-controller/files/runner-userdata.yaml.tmpl` embeds the ephemeral runner registration token in plaintext user-data. It is readable through the OpenStack metadata service and the console log by anyone with project API access. The token is single-use and short-lived. Either record this as an accepted risk in the runbook, or have the runner fetch the token out of band on first boot (for example from the controller over the private network with the instance id as the credential). Decide and document.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#467
Ingen beskrivning angiven.