Uploaded image for project: 'Release Requirements'
  1. Release Requirements
  2. REQ-235

Password removal from OOM HELM charts

XMLWordPrintable

    • Password removal from OOM HELM charts
    • 1

      As discovered in ONAP Casablanca pentest (and confirmed in latest version) OOM contains a lot of different passwords. There are 3 issues related to this:

      1) Some of passwords are stored in resource files rather than in secrets

      2) The same passwords are reused for almost all deployments

      3) It's is not possible to use already existing secrets for ONAP deployment

       

      To fix those issues we plan:

      1) Ensure that all passwords are stored in kubernetes secrets

      2) Make all passwords randomly generated per deployment unless a passwords override has been provided for the deployment

      3) Add ability to use external secrets instead of providing passwords override.

            kopasiak kopasiak
            Pawel_P Paweł Pawlak
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated:
              Resolved: