Repository navigation
feat(register): add output dir for credentials - #108
Merged
Merged
Conversation
robertodauria
requested changes
Oct 8, 2026
robertodauria
left a comment
Contributor
There was a problem hiding this comment.
-output-sec read as output seconds to me at first. Perhaps -output-secrets?
Member
Author
|
I discussed this with @robertodauria and he suggested changing the flag to |
robertodauria
self-requested a review
October 8, 2026 13:31
robertodauria
approved these changes
Oct 8, 2026
This patch adds a new flag: `-output-secure`. Its default value is the value used by `-output`, for backward compatibility with deployments that only specify the `-output` flag. The purpose of this patch is to allow a consumer like `byos-debian` to emit the service account key (and possibly other secrets in the future) into distinct dirs with distinct permissions. In turn, this ensures that network measurement services such as the `ndt-server` cannot read the service account key, which is anyway a secret it should not have access to, while still being able to source the public files it requires. We named the flag `-output-secure=` (as opposed to something like `-secure-output=`) because we want it to sort near the `-output=` flag for additional `-h/-help` clarity.
bassosimone
force-pushed
the
feat/privsep
branch
from
October 8, 2026 13:40
5214db5 to
ab6a0c6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This patch adds a new flag:
-output-secure. Its default value is the value used by-output, for backward compatibility with deployments that only specify the-outputflag.The purpose of this patch is to allow a consumer like
byos-debianto emit the service account key (and possibly other secrets in the future) into distinct dirs with distinct permissions.In turn, this ensures that network measurement services such as the
ndt-servercannot read the service account key, which is anyway a secret it should not have access to, while still being able to source the public files it requires.We named the flag
-output-secure=(as opposed to something like-secure-output=) because we want it to sort near the-output=flag for additional-h/-helpclarity.This change is