Skip to content

[Security] [V-242415] Avoid using secret as environment variables in Kubernetes #2201

@chengjingtao

Description

@chengjingtao

According to the requirements outlined in https://stigviewer.com/stigs/kubernetes/2024-08-22/finding/V-242415, it is explicitly stated that "Secrets should not be stored as environment variables."

However, the current Helm chart implementation heavily relies on setting sensitive data through environment variables.

What is our opinion on this issue, and do we have plans to fix it ?

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions