You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This is not exactly safe as this file contains secrets. We should either encrypt it or stop creating it in current form.
But we do need a backup of Terraform state in order to handle disaster recovery scenarios when Consul is unavailable.
The text was updated successfully, but these errors were encountered:
I think the simplest and most secure solution would be to stop creating Terraform state backups.
We do create ansible inventory for emergency cases and that should be enough.
As discussed, we want to keep Terraform state backups in the event consul fails.
I've modified my old PR to encrypt terraform state with CONSUL_HTTP_TOKEN.
Currently we create a Terraform state backup file with
ansible/terraform.py
:https://github.com/status-im/infra-template/blob/master/ansible/terraform.py
This is not exactly safe as this file contains secrets. We should either encrypt it or stop creating it in current form.
But we do need a backup of Terraform state in order to handle disaster recovery scenarios when Consul is unavailable.
The text was updated successfully, but these errors were encountered: