Skip to content

Commit c429c4c

Browse files
authored
Merge pull request apache#332 from mrhillsman/credleak
Resolve dockerhub credentials leak
2 parents 6304a52 + b0d04c3 commit c429c4c

2 files changed

Lines changed: 27 additions & 13 deletions

File tree

playbooks/cloud-provider-openstack-acceptance-test-e2e-conformance/run.yaml

Lines changed: 17 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -130,8 +130,13 @@
130130
# NOTE(flaper87): Export these variables
131131
# before setting -x and -e to avoid leaking
132132
# sensitive data.
133-
export DOCKER_USERNAME={{dockerhub.username}}
134-
export DOCKER_PASSWORD={{dockerhub.password}}
133+
# NOTE(mrhillsman): Credentials still were leaking
134+
# so removing the export unless absolutely needed
135+
# and setting the login earlier instead of using Makefile
136+
# https://github.com/kubernetes/cloud-provider-openstack/blob/master/Makefile#L255
137+
#export DOCKER_USERNAME={{dockerhub.username}}
138+
#export DOCKER_PASSWORD={{dockerhub.password}}
139+
docker login -u {{dockerhub.username}} -p {{dockerhub.password}}
135140
export REGISTRY=docker.io/k8scloudprovider
136141
export VERSION=latest
137142
@@ -143,7 +148,16 @@
143148
exit 0;
144149
fi
145150
146-
make upload-images 2>&1 | tee $LOG_DIR/image-build-upload.log
151+
make images 2>&1 | tee $LOG_DIR/image-build-upload.log
152+
153+
docker push $(REGISTRY)/openstack-cloud-controller-manager:$(VERSION) | tee $LOG_DIR/image-build-upload.log
154+
docker push $(REGISTRY)/cinder-flex-volume-driver:$(VERSION) | tee $LOG_DIR/image-build-upload.log
155+
docker push $(REGISTRY)/cinder-provisioner:$(VERSION) | tee $LOG_DIR/image-build-upload.log
156+
docker push $(REGISTRY)/cinder-csi-plugin:$(VERSION) | tee $LOG_DIR/image-build-upload.log
157+
docker push $(REGISTRY)/k8s-keystone-auth:$(VERSION) | tee $LOG_DIR/image-build-upload.log
158+
docker push $(REGISTRY)/octavia-ingress-controller:$(VERSION) | tee $LOG_DIR/image-build-upload.log
159+
docker push $(REGISTRY)/manila-provisioner:$(VERSION) | tee $LOG_DIR/image-build-upload.log
160+
147161
executable: /bin/bash
148162
chdir: '{{ k8s_os_provider_src_dir }}'
149163
environment: '{{ global_env }}'

zuul.d/secrets.yaml

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -632,13 +632,13 @@
632632
TFjEpKwbdoTEVhHyJYB90fxeT3TqQ0VXEQ9CXruwGcK0+ob+D9uDixEyfOdzmMLf7TtOC
633633
4F7k/VkZhnprO91G8xj46ZBNmmOs/8+dDW7g92Xqe1Axrdd5OaAoc7iBA9vvJg=
634634
password: !encrypted/pkcs1-oaep
635-
- D31XJ4yBkgNt3Jz3sWqzdPRxA0WukIEnRh9/0lB0P4DQicRl7Vlz79kJtlQj4Y8ZGJzHE
636-
pjwCRls6thayNjBj5dG1Rl2rKBNV+jUihEl0JPxXzfCr6vKD0Z4o3SaLNkyJetaS/NV5d
637-
7/leg/8oidblmWsOROLwlekq3rOSjFDnzBMF1PKUACpkth/hIclUUAKFRoYJX4ZszgKVB
638-
2UBK77EZarhuvmj3U7TNkGiHSjAz3iHuiADKcq19COaov9FSLf2YEVUBV9O62rS668iLJ
639-
FC+iPqddHDNVxcS/Is51tRsfDbnPwwilTK5uwgIghaw8R8XmgoSCLB/h6UFr6swTxPYla
640-
77yUNvX19yDFFVRCM5OmfojX7ucDxRtPdzNBJBDihLiZjZ5Zkts/Cy/Sh3VmJMngA2QVw
641-
bncDFE9K/AuJjDecf3UqsuBs2OxAfKINGUPPk9OUgM+rdDZeq/yAgpEW4ZIu+cB+7Xl1z
642-
mEr/V2fkz6ApMiqdFUDMDLiH06mf3QgVesPYYi720etSFz9qoCiAR+KNnO8NKl5GuXdrM
643-
VXf168+ej1oWq9qIdBbyg6S8l7F0O+EthCIWECkJ9buv2XepXaPgZaxhE9ppbtL7N8Oat
644-
mkKLXNyIg4aRx0jaxuQcMRVuy9zqfrxowkKQxEk4OLP/htnlJmbkHw9Y3lhtRU=
635+
- gBcJsbDNsMhPYNvXdY3T3KYY/liUcEBE0foS6BasPQnbaERVQ6D1fSJlMFbMkkEMwRbp3
636+
OBjnwZwed4IQ9WNVtmJHGWXCD/EfmZ4MM86LWZN/8PcJfNN0CSRT98XHLW5LemudvFgIT
637+
EjUq1go64+ZvTeGYc87JE9c7M2V2/PMEjiA4GFh1OGcG2JiM/N2UXDkwBmFvUAoDVAJ7B
638+
cDVQJXbARIhovEaIOp3Rs/YLd6G2ndofJchGoRpRHH7d0BM8Ep+S2XSa0NL2B0pFakSMM
639+
+ylXt4vzGwaKsAiTrT/yrH50OnVTA2qB02Ca143ZbLudTIelsKC/ISdLGz7V4on10kuww
640+
mV6eIneApdw69NX6lLz+GC3Fn8StQoJjD8Pccw4TYAqpELPbDlp3zXe/bHXsNGNZAAaa6
641+
HJEuFhPWOyfwD9Xv+Pm6mAcP4JgdcXlrqocue6CDV/xFAp20IZv+mLnreYDqlq+GEN5Gd
642+
leeJGp4vFVD636c3I6AwkJZGFZgpS1a0UblCBn4xT+yzUc9kvAqdZjwMwmBKnIFyKZvVu
643+
je39HPT7L37WBuiPhWUu0Y5V0gfjSgWbauGDSAp749AQzmaweTECxM/jZOt9Nxye++6Mj
644+
KPdF0X8oXsFbLXk2Ur2eKhstYZ3nGlKYXew4hslZXVDFsmSypsxJmJGX9GaXIg=

0 commit comments

Comments
 (0)