From 80f806fa9c342c58c0dda6f666522da6368d2b72 Mon Sep 17 00:00:00 2001 From: Feilong Wang Date: Mon, 9 Jul 2018 20:57:34 +1200 Subject: [PATCH] Make service account private key hidden The service account private key needs to be hidden for safety reasons. This patch fixes it. Task: 22886 Story: 1766546 Change-Id: I16929c6de2c442865b2978ae6c18c22b8146f645 --- magnum/drivers/k8s_fedora_atomic_v1/templates/kubecluster.yaml | 2 ++ magnum/drivers/k8s_fedora_atomic_v1/templates/kubemaster.yaml | 2 ++ 2 files changed, 4 insertions(+) diff --git a/magnum/drivers/k8s_fedora_atomic_v1/templates/kubecluster.yaml b/magnum/drivers/k8s_fedora_atomic_v1/templates/kubecluster.yaml index ec97256f72..5e114013ff 100644 --- a/magnum/drivers/k8s_fedora_atomic_v1/templates/kubecluster.yaml +++ b/magnum/drivers/k8s_fedora_atomic_v1/templates/kubecluster.yaml @@ -477,12 +477,14 @@ parameters: kube_service_account_key: type: string + hidden: true description: > The signed cert will be used to verify the k8s service account tokens during authentication. kube_service_account_private_key: type: string + hidden: true description: > The private key will be used to sign generated k8s service account tokens. diff --git a/magnum/drivers/k8s_fedora_atomic_v1/templates/kubemaster.yaml b/magnum/drivers/k8s_fedora_atomic_v1/templates/kubemaster.yaml index e8ff06186f..8427075e80 100644 --- a/magnum/drivers/k8s_fedora_atomic_v1/templates/kubemaster.yaml +++ b/magnum/drivers/k8s_fedora_atomic_v1/templates/kubemaster.yaml @@ -371,12 +371,14 @@ parameters: kube_service_account_key: type: string + hidden: true description: > The signed cert will be used to verify the k8s service account tokens during authentication. kube_service_account_private_key: type: string + hidden: true description: > The private key will be used to sign generated k8s service account tokens.