You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I found that when external-dns use TXT registry, it create TXT records without any encryption, that can be result of leak some information about infrastructure, e.g. internal namespace name and/or project name.
What would you like to be added:
I think, that need extra key (e.g. --txt-encryption-key), for give ability, to encrypt data, stored in TXT records, e.g. via AES.
Why is this needed:
For prevent data leaks.
What do you think?
The text was updated successfully, but these errors were encountered:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.
Hi guys,
I found that when external-dns use TXT registry, it create TXT records without any encryption, that can be result of leak some information about infrastructure, e.g. internal namespace name and/or project name.
What would you like to be added:
I think, that need extra key (e.g.
--txt-encryption-key
), for give ability, to encrypt data, stored in TXT records, e.g. via AES.Why is this needed:
For prevent data leaks.
What do you think?
The text was updated successfully, but these errors were encountered: