Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
submitaticket
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
submitaticket
2mo ago
Long enough to authenticate the node into the Tailnet. Short enough to revoke itself before the Agent can use it.
2.
▲
by
submitaticket
2mo ago
Not the quickest win if you're spinning up ephemeral runners for CI.
3.
▲
by
submitaticket
2mo ago
Where is he preaching the religion of short-living credentials. He literally agrees with the high cost/friction to implement. > Unfortunately, dynamic credentials are a lot of work to set up and maintain. When security requires work
4.
▲
by
submitaticket
2mo ago
It would not have prevented the initial exploit. The agent gained access to the K8s cluster and read the Tailscale Auth Key from Cluster Secrets. A short-lived credential would reduce the risk that the key is still valid when an agent gains