generated from openmcp-project/repository-template
-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Description
Description
As users of Crossplane, we highly benefit from its desired state methodology.
Getting security related functionality into this work mode is often asked for - in particular schduled Secret rotation.
We have seen a rotation mechanism with great user feedback in the BTP service operator.
Desired outcome
- All listed resources that we want to rotate can be configured for
rotationFrequency
androtatedBindingTTL
- Community-approved approach that puts development experience and security first
- Notable increase in Rotation of Secrets proofing that IaD makes cloud landscapes more secret!
Approach
- Finalize Rotation around
ServiceCredentialBinding
in CloudFoundry [https://github.com/[FEATURE] EnhanceServiceCredentialBinding
for rotate SAP/crossplane-provider-cloudfoundry#87] - Make BTP
ServiceBinding
rotatbale [https://github.com/[FEATURE] Make ServiceBinding rotatable SAP/crossplane-provider-btp#244] - Bring together Engineers of both Providers - have list of all Resources to rotate prepared
- Decide: On Implementation
Implementation Options
A: Standalone Operator/Function
TBD
B: GO Lib to be used in all Providers
TBD
C: Contribute to 3rd party Tools
TBD
Out of scope
Metadata
Metadata
Labels
No labels