Hacker News
new
past
comments
ask
show
jobs
points
by
gleenn
14 hours ago
|
comments
by
XCSme
5 hours ago
|
[-]
But how do you do that without also having a long-lived key or access token to those services?
reply
by
noAnswer
1 hours ago
|
parent
|
[-]
The long-lived credentials life inside a stripped down machine. Cron/lego/Ansible handles the renewal. The machines on the edge can't renew their keys themselves.
reply
by
XCSme
1 hours ago
|
parent
|
[-]
Oh, this makes sense, so instead of "the app is rotating its keys" is more like "the keys in our app are being rotated by an external service".
reply