runner-controller: registration token in cloud-init user-data #467
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#467
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
roles/runner-controller/files/runner-userdata.yaml.tmplembeds the ephemeral runner registration token in plaintext user-data. It is readable through the OpenStack metadata service and the console log by anyone with project API access.The token is single-use and short-lived. Either record this as an accepted risk in the runbook, or have the runner fetch the token out of band on first boot (for example from the controller over the private network with the instance id as the credential). Decide and document.