You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We have to use predefined sets of keys to encrypt/decrypt secrets to get keys control hardened.
So, would be awesome to use full arn (we use AWS KMS) sets of keys in values and not create new ones
The text was updated successfully, but these errors were encountered:
Interesting. We can support this, but this will make the encryption weaker - currently, there is one key per service account/namespace combination. How would you imagine this setup? Having a static mapping of service accounts/namespace to ARNs?
We have to use predefined sets of keys to encrypt/decrypt secrets to get keys control hardened.
So, would be awesome to use full arn (we use AWS KMS) sets of keys in values and not create new ones
The text was updated successfully, but these errors were encountered: