#ops (2018-08)
Archive: https://archive.sweetops.com/ops/
2018-08-22
data:image/s3,"s3://crabby-images/5fb9a/5fb9ac1bcc6919a0f8ac4bf58b1d5e59cb010118" alt="melynda.hunter avatar"
@melynda.hunter has joined the channel
2018-08-27
data:image/s3,"s3://crabby-images/c3045/c30457671c549c83747cff024180a42acd53f85a" alt="tolstikov avatar"
@tolstikov has joined the channel
data:image/s3,"s3://crabby-images/587cb/587cb111e211bf2a505a426ac4991d263866c57b" alt="loweryr avatar"
@loweryr has joined the channel
2018-08-28
data:image/s3,"s3://crabby-images/b743b/b743b51569ce547d011eb0519e5dc263b254ebe3" alt="justin.dynamicd avatar"
@justin.dynamicd has joined the channel
data:image/s3,"s3://crabby-images/b743b/b743b51569ce547d011eb0519e5dc263b254ebe3" alt="justin.dynamicd avatar"
It’s a bit of effort to get things like MFA/dynamic passwords pushed “down the stack” .. but oddly enough you end up with less maintenance later if you can pull it off. Well worth the journey IMO
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
yea, also with the new push-style notifications of Okta/Duo/Google, it doesn’t annoy me as much
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
I’d like to get push for AWS MFA
data:image/s3,"s3://crabby-images/b743b/b743b51569ce547d011eb0519e5dc263b254ebe3" alt="justin.dynamicd avatar"
SAML is as close as I’ve gotten. Set your MFA there and use the SAML token to pass into AWS.
data:image/s3,"s3://crabby-images/b743b/b743b51569ce547d011eb0519e5dc263b254ebe3" alt="justin.dynamicd avatar"
fall back to those horrid keys they sell for your root … cause … nothing else works
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
yea, those are the escape hatch
data:image/s3,"s3://crabby-images/b743b/b743b51569ce547d011eb0519e5dc263b254ebe3" alt="justin.dynamicd avatar"
then for programmatic access I’ve become a Vault fan. Let users dynamically request temporary creds, and you can gate vault with MFA as well
data:image/s3,"s3://crabby-images/b743b/b743b51569ce547d011eb0519e5dc263b254ebe3" alt="justin.dynamicd avatar"
so far used it with both Okta/Centrify. Not tried Duo
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
vault as in hashicorp vault?
data:image/s3,"s3://crabby-images/b743b/b743b51569ce547d011eb0519e5dc263b254ebe3" alt="justin.dynamicd avatar"
yup
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
cool
data:image/s3,"s3://crabby-images/b743b/b743b51569ce547d011eb0519e5dc263b254ebe3" alt="justin.dynamicd avatar"
I keep forgetting there’s techncially lots of vaults out there …
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
yea, and we’re big on using aws-vault
(so for a second I was surprised to learn it supported Okta) - but we’re talking about another vault
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
yea, I’ve seen that feature of hashicorp’s vault
data:image/s3,"s3://crabby-images/b743b/b743b51569ce547d011eb0519e5dc263b254ebe3" alt="justin.dynamicd avatar"
It’s nice. Hardest part becomes policy management … but it’s been solid on the stability front
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
we’ve just done a poc with vault. all-in-all, liked it. it was pretty simple to setup. the security architecture too was pretty sweet (the “two man rule” for unlocking vaults)
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
but it scared me from an operational perspective (just from lack of experience with it) - what happens if all vaults get restarted
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
if you don’t automate the unsealing, that’s a forced outage
data:image/s3,"s3://crabby-images/b743b/b743b51569ce547d011eb0519e5dc263b254ebe3" alt="justin.dynamicd avatar"
or pay for enterprise which can auto-unseal against an HSM
data:image/s3,"s3://crabby-images/b743b/b743b51569ce547d011eb0519e5dc263b254ebe3" alt="justin.dynamicd avatar"
but yeah I hear you
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
so running vault under kubernetes, we automated the unsealing
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
but it felt “wrong”
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
data:image/s3,"s3://crabby-images/b743b/b743b51569ce547d011eb0519e5dc263b254ebe3" alt="justin.dynamicd avatar"
I actually wen t full paranoid where I deployed it and did NOT use containers. It sat on instances build using packer from ther terratorm.io registry
data:image/s3,"s3://crabby-images/b743b/b743b51569ce547d011eb0519e5dc263b254ebe3" alt="justin.dynamicd avatar"
was too concerned about a container reshuffle causing things to happen
data:image/s3,"s3://crabby-images/b743b/b743b51569ce547d011eb0519e5dc263b254ebe3" alt="justin.dynamicd avatar"
but in general I don’t think ti ever went down except when I messed up a health check so the proxy “thought” it was down (oops) … so I left the unseal manual
data:image/s3,"s3://crabby-images/b743b/b743b51569ce547d011eb0519e5dc263b254ebe3" alt="justin.dynamicd avatar"
current place has “cyberark” in place … it’s API is horrible. Just the worst
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
i am not familiar with cyberark
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
what’s that?
data:image/s3,"s3://crabby-images/b743b/b743b51569ce547d011eb0519e5dc263b254ebe3" alt="justin.dynamicd avatar"
similar in concept to hashicorp vault or AWS-vault … but honestly I’m not impressed so far: https://www.cyberark.com/
CyberArk is the only security software company focused on eliminating cyber threats using insider privileges to attack the heart of the enterprise.
data:image/s3,"s3://crabby-images/b743b/b743b51569ce547d011eb0519e5dc263b254ebe3" alt="justin.dynamicd avatar"
it “feels” like old software, if that makes sense
2018-08-29
data:image/s3,"s3://crabby-images/4f952/4f9522dfe5f080239b2f6feeb9e8ab1f04b91f03" alt="Raghu avatar"
@Raghu has joined the channel