Suggested AWS SecretsManager policy allows access to untagged secrets #51614
techxorcist
started this conversation in
Guides & Tutorials
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
In the Infrastructure>AWS portion of the docs, the recommended IAM policy for the SecretsManager contains the following element:
This condition allows access to untagged Secrets, which will help the SecretsManager work with an installation where tags for secrets are not specified in values.yaml but also will allow traversal to any untagged secrets in the same storage.
I believe the fix would be to amend the documentation to recommend the following policy:
In addition, it would be user-friendly to suggest the following in the Integrations>Secrets documentation:
Beta Was this translation helpful? Give feedback.
All reactions