Handling Sensitive Data

107 views
Skip to first unread message

Jistan Idiot

unread,
May 8, 2012, 8:28:14 AM5/8/12
to Puppet Users
So we're looking at using Puppet. There are three things we're trying
to figure out how to manage -- SSL keys for the webservers, SSH keys
for the users, and the user's passwords (and specific /etc/shadow and /
etc/passwd for each box).

There's a ton of concerns with each one of these. Is there some place
with a good guide for doing all of this?

I came across a very old thread
http://groups.google.com/group/puppet-users/browse_thread/thread/da756bb067565ede
which implies you shouldn't put your sensitive data in the files
directory of the module. Is that still true?



Erik Dalén

unread,
May 8, 2012, 9:36:02 AM5/8/12
to puppet...@googlegroups.com
That still holds true (unless you want to micromanage access permissions).

There is however a way to create a directory per host that is only
accessible by that host:
https://groups.google.com/forum/#!msg/puppet-users/XBkdcDypm0g/AVJFsSORkOkJ

--
Erik Dalén

Ryan Coleman

unread,
May 8, 2012, 8:19:17 PM5/8/12
to puppet...@googlegroups.com


On Tuesday, May 8, 2012 6:36:02 AM UTC-7, Erik Dalén wrote:

That still holds true (unless you want to micromanage access permissions).

There is however a way to create a directory per host that is only
accessible by that host:
https://groups.google.com/forum/#!msg/puppet-users/XBkdcDypm0g/AVJFsSORkOkJ

--
Erik Dalén

+1 to using a custom mount point to keep sensitive files out of modules and restricting those mount points.


Reply all
Reply to author
Forward
0 new messages