logoalt Hacker News

otabdeveloper4today at 7:41 AM2 repliesview on HN

There is -- you can expose a UNIX socket for serving credentials and allow access to it only from a whitelist of systemd services.


Replies

rcxdudetoday at 8:17 AM

They would still exist in plaintext, just the permissions would make it a little harder to access.

lemageduragetoday at 10:37 AM

That works on a single persistent box, but unfortunately, that means giving up on autoscaling, which is not so nice for cloud applications.