Ranter
Join devRant
Do all the things like
++ or -- rants, post your own rants, comment on others' rants and build your customized dev avatar
Sign Up
Pipeless API
From the creators of devRant, Pipeless lets you power real-time personalized recommendations and activity feeds using a simple API
Learn More
Comments
-
@sariel Nice idea.
@queekusme How sinful depends on whether you then push it to untrusted remotes.
Before my work stuff moved on to GKE, we had an encrypted JSON file in the repo with the secrets. Thing is, the passphrase was in README.md. -
@Hazarth the problem with your assumptions is that my network is public… my pis are airgapped at the moment and if I ever put them on the internet I’m refreshing the keys anyway…
I’m probably more security paranoid than I need to be but for the time being whilst I work on my ansible playbooks, I’m resetting my pis on a monthly basis…
my final outline is still months away as I still have stuff to add and even then stuff will always be subject to change…
Related Rants
Sooooooo…. The other day I committed a change with this message:
“Committing the ultimate sin in committing secret keys again however this repo is and will always be private and my pis will be hidden on my network so it shouuuuuuld be fine... right...”
joke/meme
raspberry pi
git
ultimate sin