TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Client Certificates at Netflix

38 pointsby rchiniquyabout 9 years ago

3 comments

bazzarghabout 9 years ago
It&#x27;s unclear from this and the slides what the UX for the engineers is? The repo contains a bless-client that&#x27;ll fetch a newly minted cert, but the slides talk about integration with SSO - is there another piece that invokes bless and drops the cert on disk?<p><a href="https:&#x2F;&#x2F;github.com&#x2F;Netflix&#x2F;bless&#x2F;blob&#x2F;master&#x2F;bless_client&#x2F;bless_client.py" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;Netflix&#x2F;bless&#x2F;blob&#x2F;master&#x2F;bless_client&#x2F;bl...</a>
评论 #11741057 未加载
blakesterzabout 9 years ago
<a href="https:&#x2F;&#x2F;speakerdeck.com&#x2F;rlewis&#x2F;how-netflix-gives-all-its-engineers-ssh-access-to-instances-running-in-production" rel="nofollow">https:&#x2F;&#x2F;speakerdeck.com&#x2F;rlewis&#x2F;how-netflix-gives-all-its-eng...</a><p>That&#x27;s a great slidedeck, looks great and I can actually learn something from it just reading the slides.
zokierabout 9 years ago
I&#x27;m not sure how much BLESS really improves the overall situation. It just shifts the problem from securing SSH secrets to securing AWS&#x2F;IAM secrets, which seems pretty much the same to me.
评论 #11740970 未加载
评论 #11740980 未加载