Skip to content

Restrict database access URL to required services only in awstf #782

Open
@jyecusch

Description

@jyecusch

Feature Request

Suggestion

Currently, all services in a deployed stack will have access to the NITRIC_DATABASE_BASE_URL env var. This environment variable should ideally only be added to services that have requested access to the database in the deployment spec.

Value

Slightly improve least-priveledge access control

Other info

See: cloud/aws/deploytf/service.go:56

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions