Hacker News new | ask | show | jobs
by otabdeveloper4 54 days ago
You can proxy the UNIX socket to a network server if you want to. You can even use SSL encryption at all times too.
1 comments

Once it's networked you lose the "whitelist of systemd services" and it's then no different from any networked secret store.
No, this is a solved problem: https://spiffe.io/

You can do service attestation securely, even for networked services.

Nice. Really grateful for your participation in this comment tree