Feature Request
Currently, securing the retrieval of Ignition configs during a merge or replace operation requires embedding the key directly into the Ignition file so it can be sent in the HTTP header. A more flexible approach would allow running a script to retrieve this key dynamically.
Desired Feature
Add a new field to Ignition named fetchKey (or another suitable name) nested under merge and replace. This field would accept a script (inline or file path) that executes and returns the authentication key, which will then be added to the HTTP header.
Other Information
This feature need originates from trusted-execution-clusters. We run a service that delivers Ignition configs for merging, but we want to restrict access exclusively to trusted machines. Therefore, we want to have a script that attests this machine and sends a token as the key, proving that this machine passed attestation.
I would appreciate any opinion and suggestion
Feature Request
Currently, securing the retrieval of Ignition configs during a merge or replace operation requires embedding the key directly into the Ignition file so it can be sent in the HTTP header. A more flexible approach would allow running a script to retrieve this key dynamically.
Desired Feature
Add a new field to Ignition named fetchKey (or another suitable name) nested under merge and replace. This field would accept a script (inline or file path) that executes and returns the authentication key, which will then be added to the HTTP header.
Other Information
This feature need originates from trusted-execution-clusters. We run a service that delivers Ignition configs for merging, but we want to restrict access exclusively to trusted machines. Therefore, we want to have a script that attests this machine and sends a token as the key, proving that this machine passed attestation.
I would appreciate any opinion and suggestion