Skip to content

feat(register): add output dir for credentials - #108

Merged
bassosimone merged 1 commit into
mainfrom
feat/privsep
Oct 8, 2026
Merged

bassosimone merged 1 commit into
mainfrom
feat/privsep

Conversation

@bassosimone

@bassosimone bassosimone commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

This patch adds a new flag: -output-secure. Its default value is the value used by -output, for backward compatibility with deployments that only specify the -output flag.

The purpose of this patch is to allow a consumer like byos-debian to emit the service account key (and possibly other secrets in the future) into distinct dirs with distinct permissions.

In turn, this ensures that network measurement services such as the ndt-server cannot read the service account key, which is anyway a secret it should not have access to, while still being able to source the public files it requires.

We named the flag -output-secure= (as opposed to something like -secure-output=) because we want it to sort near the -output= flag for additional -h/-help clarity.


This change is Reviewable

@robertodauria robertodauria left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

-output-sec read as output seconds to me at first. Perhaps -output-secrets?

Comment thread cmd/register/main.go
@bassosimone

bassosimone commented Oct 8, 2026 •

Copy link
Copy Markdown
Member Author

I discussed this with @robertodauria and he suggested changing the flag to -output-secur=. We also discussed whether -secure-output= would have been more idiomatic. Given that -output= already exists, I suggested keeping -output-secure= so they sort together in the CLI.

@robertodauria
robertodauria self-requested a review October 8, 2026 13:31
This patch adds a new flag: `-output-secure`. Its default value is
the value used by `-output`, for backward compatibility with
deployments that only specify the `-output` flag.

The purpose of this patch is to allow a consumer like `byos-debian`
to emit the service account key (and possibly other secrets in
the future) into distinct dirs with distinct permissions.

In turn, this ensures that network measurement services such as
the `ndt-server` cannot read the service account key, which is
anyway a secret it should not have access to, while still being
able to source the public files it requires.

We named the flag `-output-secure=` (as opposed to something
like `-secure-output=`) because we want it to sort near the
`-output=` flag for additional `-h/-help` clarity.
@bassosimone
bassosimone merged commit 2aba21f into main Oct 8, 2026
7 checks passed
@bassosimone
bassosimone deleted the feat/privsep branch October 8, 2026 13:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants