Tom Eyckmans
Tom Eyckmans
google/tink supports key rotation, we should have a task to rotate the encryption key for an environment. https://github.com/google/tink/blob/master/docs/KEY-MANAGEMENT.md
- also support authentication / api-server url from by kubeconf file. the kubeconf file should use the following filename .encrypted.default.kubeconf - autodetect authentication option in this order (.encrypted.default.kubeconf > .encrypted.default.access-token...
provide a way to configure keyset envelop encryption https://github.com/google/tink/blob/master/docs/JAVA-HOWTO.md#envelope-encryption