XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Provision Config/Secrets to XenStore from XO

    Scheduled Pinned Locked Moved Xen Orchestra
    2 Posts 2 Posters 150 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • smrqdtS Offline
      smrqdt
      last edited by smrqdt

      Is there a way to insert data into xenstore through XO when creating a VM?

      I’m interested in inserting configuration (like Fedora CoreOS Ignition) or secrets (e.g. a vault token) into a VM.

      Would xenstore be a “safe” place for secrets? It seems it is only accessible by the root user of the guest, so a good start. I assume it’s also properly isolated from other guests?

      1 Reply Last reply Reply Quote 0
      • olivierlambertO Offline
        olivierlambert Vates 🪐 Co-Founder CEO
        last edited by

        Hi,

        1. Indeed, only root user in the guest can read it
        2. Any user that can see the XAPI object will be able to read it

        So I would say it's "reasonably safe", but it all depends on your global usage context and level of confidentiality you need.

        1 Reply Last reply Reply Quote 1
        • First post
          Last post