The profile-plus-orchestrator pattern is a clean answer, and re-inject existing at all puts you ahead of most setups I have seen. The remaining edge: a process that read the credential at boot still holds the old value…
The Profiles idea is the interesting part. Injection at creation is the easy half; the hard half is revocation mid-session. If a credential in a profile rotates or gets pulled while a box is up for days, does the…
[dead]
The thing that surprised me running relays for robot fleets: relay was not the fallback, it was the common case. Hole punching fails a lot behind enterprise NAT.
[flagged]
The profile-plus-orchestrator pattern is a clean answer, and re-inject existing at all puts you ahead of most setups I have seen. The remaining edge: a process that read the credential at boot still holds the old value…
The Profiles idea is the interesting part. Injection at creation is the easy half; the hard half is revocation mid-session. If a credential in a profile rotates or gets pulled while a box is up for days, does the…
[dead]
The thing that surprised me running relays for robot fleets: relay was not the fallback, it was the common case. Hole punching fails a lot behind enterprise NAT.
[flagged]
[flagged]