Project

General

Profile

Actions

action #166439

closed

openQA Project (public) - coordination #105624: [saga][epic] Reconsider how openQA handles secrets

action #160334: [qe-core] Add CI/CD check to avoid uses of nots3cr3t or other hardcoded password in pull requests

[qe-core] Remove hardcode password on the data directory

Added by tinawang123 3 months ago. Updated about 1 month ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Refactor/Code Improvements
Start date:
2024-09-06
Due date:
% Done:

0%

Estimated time:
Difficulty:
Sprint:
QE-Core: November Sprint 24 (Nov 06 - Dec 04)

Description

Motivation
In https://sd.suse.com/servicedesk/customer/portal/1/SD-150437 we are asked to handle "compromised root passwords in QA segments"
This will not stop somebody from adding a different password though, so we need to think a bit before working on this, however we can start with using it on the data directory first.
So we need remove password on data directory first.


Related issues 1 (0 open1 closed)

Related to qe-yam - action #168853: Remove hardcode password for first user and the root passwords in Agama unattended jsonnet profilesResolvedleli2024-10-24

Actions
Actions

Also available in: Atom PDF