Skip to content
Snippets Groups Projects

Allow masking secrets for base component

Merged Jay McCure requested to merge jmc-hide-aigw-keys into master
All threads resolved!

What does this MR do and why?

Moves secrets to base component so other components can utilise mask_secrets when doing docker#run. Additionally hides the two test signing keys used by the AiGateway component. Although these keys are safe to be shared, they have caused confusion (SIRT incident raised) when they were detected in the logs.

How to set up and validate

GitLab test MR using this branch -> gitlab!162801 (closed)

Keys not being printed to logs: https://gitlab.com/gitlab-org/gitlab/-/jobs/7588730343#L362 (AIGW_SELF_SIGNED_JWT__VALIDATION_KEY and AIGW_SELF_SIGNED_JWT__SIGNING_KEY)

Regression checks: GITLAB_QA_USER_AGENT \ QA_EE_ACTIVATION_CODE: https://gitlab.com/gitlab-org/gitlab/-/jobs/7588730343#L379 / https://gitlab.com/gitlab-org/gitlab/-/jobs/7588730295#L375

MR acceptance checklist

This checklist encourages us to confirm any changes have been analyzed to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Jay McCure

Merge request reports

Loading
Loading

Activity

Filter activity
  • Approvals
  • Assignees & reviewers
  • Comments (from bots)
  • Comments (from users)
  • Commits & branches
  • Edits
  • Labels
  • Lock status
  • Mentions
  • Merge request status
  • Tracking
  • Jay McCure resolved all threads

    resolved all threads

  • Jay McCure added 1 commit

    added 1 commit

    • 151292e5 - Apply 1 suggestion(s) to 1 file(s)

    Compare with previous version

  • Jay McCure marked this merge request as ready

    marked this merge request as ready

  • Jay McCure changed the description

    changed the description

  • Jay McCure changed the description

    changed the description

  • Jay McCure changed milestone to %17.4

    changed milestone to %17.4

  • Jay McCure changed title from Hide secrets for base component to Allow masking secrets for base component

    changed title from Hide secrets for base component to Allow masking secrets for base component

  • Jay McCure requested review from @john.mcdonnell

    requested review from @john.mcdonnell

  • John McDonnell approved this merge request

    approved this merge request

  • John McDonnell requested review from @mlapierre and removed review request for @john.mcdonnell

    requested review from @mlapierre and removed review request for @john.mcdonnell

  • Mark Lapierre resolved all threads

    resolved all threads

  • Mark Lapierre mentioned in commit 35c9c19b

    mentioned in commit 35c9c19b

  • Please register or sign in to reply
    Loading