apm-server icon indicating copy to clipboard operation
apm-server copied to clipboard

Obfuscate secret token after removing Fleet's ability to read secrets

Open simitt opened this issue 1 year ago • 3 comments

Fleet/Kibana now supports secrets in the Kibana UI, as described in https://github.com/elastic/kibana/issues/154715#issuecomment-1678430435. We should set secret: true for secret-token in the apm package (https://github.com/elastic/apm-server/blob/main/apmpackage/apm/manifest.yml#L52).

simitt avatar Aug 22 '23 04:08 simitt

@gbamparop Do you think this is something we can do in 8.11? I'm very doubtful so I'd suggest pushing this to 8.12 (Kibana issue for context)

sorenlouv avatar Aug 27 '23 10:08 sorenlouv

@gbamparop Do you think this is something we can do in 8.11? I'm very doubtful so I'd suggest pushing this to 8.12 (Kibana issue for context)

I agree, let's plan it for 8.12 if it's not urgent.

gbamparop avatar Aug 29 '23 12:08 gbamparop

@gbamparop Do you think this is something we can do in 8.11? I'm very doubtful so I'd suggest pushing this to 8.12 (Kibana issue for context)

I agree, let's plan it for 8.12 if it's not urgent.

It's been unencrypted for years so I don't see the urgency.

sorenlouv avatar Aug 29 '23 13:08 sorenlouv