michael
u/mpmackenna
Excellent, thank you so much for that clarification! I grepped for the string but didn't realize it was base64 encoded in the storage file. I was able to decode some of the base64 encoded secrets without issue. That's good to know! Now I see a backup of the files is sufficient, and I should treat those files as plaintext passwords on disk. I use the Pass utility some on my box so I will look into that as a possible option. Thanks again!
What does podman use to encrypt the files? Is there a key somewhere for the user? If I had a backup of all the secret files and my machine caught on fire, what would I need to decrypt those files? I use Ansible Vault to encrypt files for Ansible, and an encryption string is provided during encryption. You can decrypt all the vaulted files on a different machine if you have the provided encryption string. I would like to know if there is a similar process for Podman's Secret function. I didn't see anything in the documentation. Thanks!
Keybase proof
I am:
-
on reddit.
-
on keybase.
Proof:
hKRib2R5hqhkZXRhY2hlZMOpaGFzaF90eXBlCqNrZXnEIwEgd6bNtZfT1SV1GNehqxW7lR1A6+izXJrXxqtS/L/Om60Kp3BheWxvYWTESpcCF8Qg2J9ucZX9NOdahm42iPhodBWvsa9kbkbcghScr7lTos3EIK0htsNKajCUXFBcRsOwczgO0XrRZNeuEFHAWY3ynCD6AgHCo3NpZ8RAaeDtYu3xWz6j5HbjHQzjo3Sn57pSQz8MlR84W5DdDmI9KiO+3XoupNye607tW+nbcqqO/jmlIMVoFxU0QtumDKhzaWdfdHlwZSCkaGFzaIKkdHlwZQildmFsdWXEIH74Mg3vHGTo67I703MSUZbgM+kyKGskdwKDBtjbOJrCo3RhZ80CAqd2ZXJzaW9uAQ==