diff --git a/gitea/application.yaml b/gitea/application.yaml index 8c73ee4..3ba78da 100644 --- a/gitea/application.yaml +++ b/gitea/application.yaml @@ -16,28 +16,22 @@ spec: # Gitea DOES NOT go through Traefik. It has its own IP because ssh :22 would conflict with kube worker ssh. On its own IP, at the moment it doesn't flirt with Traefik — also has its own certificate. --- -# After the 2026-09 breach (CVE-2026-59774) all three secrets below leaked -# because they shared one generated value. INTERNAL_TOKEN and JWT_SECRET were -# moved to their own claims (gitea-internal-token, gitea-oauth2-jwt) and rotated; -# the StatefulSet now reads those two from the new claims, so the copies here are -# unused. SECRET_KEY is intentionally still sourced from this claim and NOT -# rotated: a new value would make data-at-rest (push-mirror creds, 2FA) -# undecryptable and break the 2 push mirrors, whose credentials must be re-entered -# by hand. Do not shrink this mapping: the operator would regenerate the plaintext -# and change SECRET_KEY. Rotate SECRET_KEY in a maintenance window instead. +# After the 2026-09 breach (CVE-2026-59774) all three security secrets leaked +# because they shared one generated value from a single "gitea-random" claim. +# Each now has its own claim and a fresh value: gitea-secret-key, +# gitea-internal-token and gitea-oauth2-jwt. The old shared gitea-random claim +# was removed. SECRET_KEY has no length constraint (Gitea hashes it to derive the +# AES key), so size 32 is fine; the earlier worry about push mirrors was wrong: +# their credentials live in each repo's on-disk git config, not SECRET_KEY. apiVersion: codemowers.cloud/v1beta1 kind: SecretClaim metadata: - name: gitea-random + name: gitea-secret-key spec: size: 32 mapping: - key: GITEA__SECURITY__SECRET_KEY value: "%(plaintext)s" - - key: GITEA__SECURITY__INTERNAL_TOKEN - value: "%(plaintext)s" - - key: GITEA__OAUTH2__JWT_SECRET - value: "%(plaintext)s" --- apiVersion: codemowers.cloud/v1beta1 kind: SecretClaim @@ -264,7 +258,7 @@ spec: - name: GITEA__SECURITY__SECRET_KEY valueFrom: secretKeyRef: - name: gitea-random + name: gitea-secret-key key: GITEA__SECURITY__SECRET_KEY ports: - containerPort: 8080