[JIRA] (JENKINS-57893) Mask Kubernetes secrets bound to containers in build log

10 views
Skip to first unread message

jglick@cloudbees.com (JIRA)

unread,
Jun 6, 2019, 2:20:02 PM6/6/19
to jenkinsc...@googlegroups.com
Jesse Glick created an issue
 
Jenkins / New Feature JENKINS-57893
Mask Kubernetes secrets bound to containers in build log
Issue Type: New Feature New Feature
Assignee: Jesse Glick
Components: kubernetes-plugin
Created: 2019-06-06 18:19
Labels: security
Priority: Major Major
Reporter: Jesse Glick

If you bind Kubernetes secrets to environment variables, and the values of secrets are printed by some process running in the pod, the text should be masked from the build log to prevent accidental disclosure. This is analogous to the masking behavior performed by the withCredentials step.

Add Comment Add Comment
 
This message was sent by Atlassian Jira (v7.11.2#711002-sha1:fdc329d)

jglick@cloudbees.com (JIRA)

unread,
Jun 6, 2019, 2:20:02 PM6/6/19
to jenkinsc...@googlegroups.com
Jesse Glick started work on New Feature JENKINS-57893
 
Change By: Jesse Glick
Status: Open In Progress

jglick@cloudbees.com (JIRA)

unread,
Jun 6, 2019, 2:32:02 PM6/6/19
to jenkinsc...@googlegroups.com

jglick@cloudbees.com (JIRA)

unread,
Jun 11, 2019, 8:25:02 AM6/11/19
to jenkinsc...@googlegroups.com
Change By: Jesse Glick
Status: In Review Fixed but Unreleased
Resolution: Fixed

vincent@latombe.net (JIRA)

unread,
Jun 18, 2019, 5:34:05 AM6/18/19
to jenkinsc...@googlegroups.com
Change By: Vincent Latombe
Status: Fixed but Unreleased Closed
Released As: 1.16.0
Reply all
Reply to author
Forward
0 new messages