Hacker News new | ask | show | jobs
by throwaway892238 1261 days ago
@dang this is currently #198 off the front page, yet this is basically an emergency (literally every customer's secrets are exposed?)... either circleci has no more customers, or people are very calm about this...

we need to rotate:

  - secrets in context environment variables
  - secrets in project environment variables
  - project deploy keys
  - circleci api tokens
then we have to go back and look at all audit logs for... basically everything... and try to find something that looks weird. :/
1 comments

this is such a clusterfuck... and the circleci api doesn't even allow to automate most of the steps. and the ones that should work, error with "internal server error". of course, support is completely unresponsive