Skip to content

[cocl-operator] Integrate trustee and the cocl operator with secret database for storing the secret resource #12

@alicefr

Description

@alicefr

In confidential clusters, secrets such as encryption keys and passwords must be securely generated and stored. This issue proposes integrating the CL Operator, Trustee, and a secret management backend like Vault to support attestation-gated secret access.

Goal

  • Enable the CL Operator to request and trigger secret (e.g., password) generation. The secret needs to be stored in a form which can be retrieved by Trustee.
  • Store generated secrets securely in Vault.
  • Allow Trustee to retrieve and deliver secrets only after successful attestation of the requesting workload.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions