Hacker News new | ask | show | jobs
by lmz 57 days ago
Once it's networked you lose the "whitelist of systemd services" and it's then no different from any networked secret store.
1 comments

No, this is a solved problem: https://spiffe.io/

You can do service attestation securely, even for networked services.

Nice. Really grateful for your participation in this comment tree