Hacker News new | ask | show | jobs
by zshev 779 days ago
I’m not familiar with DO but one approach to the secret zero thing that works elsewhere is the VPS gets assigned an OIDC identity by the provider (or the VPS has access to one if it asks). That identity is in turn used to sign in to Vault.