Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Develop a plugin for rundeck #822

Open
crawdaddy1 opened this issue Nov 11, 2022 · 0 comments
Open

Develop a plugin for rundeck #822

crawdaddy1 opened this issue Nov 11, 2022 · 0 comments

Comments

@crawdaddy1
Copy link

As a member of an SRE or Infrastructure team, I would like to use an automated workflow capability to update my PKI for supporting the Connaisseur feature set, our platform of choice is RunDeck. Rundeck provides plugin capabilities for provisioning and running jobs, a similar plugin could be used for Backstage to grow the base of interest in this toolset.

Optional: Implementation ideas
Given that rundeck and backstage have plugins for Vault, we can create a plugin that may or may not be dependent on a public key change - the automation would modify the keys configured in the helm chart, update/tag the helm chart (per a set of configuration settings) and redeploy Connaisseur to account for the public key change (or additional index/key configuration). Thus, when someone changes a key, the dependency that Connaisseur had on the key is taken care of through this plugin integration.

Optional: Additional context
Many companies are examining two serious considerations

  1. an automated workflow engine for infrastructure configuration, automation, and maintenance of artifacts - they have so many touch points to consider when changing a key (for whatever reason) that its vital to eliminate those dependencies through automation.
  2. Companies are unaware of the dangers of not enabling the k8s admission/rejection capability - as more awareness grows of the security threat, Connaisseur will be a key component of any teams' CICD Workflow
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant