• 1 Post
  • 398 Comments
Joined 3 years ago
cake
Cake day: June 29th, 2023

help-circle


  • I just recently went through a much more benign, but scary nonetheless version of this.

    I realized that my Ansible directory, that I had made public on GitHub to share as an example to some folks, had secrets committed and pushed.

    It was the direct URL and credentials of an app I developed to store non-PII customer data. Now, it wouldn’t be the end of the world if someone noticed this and scraped the data, but it wouldn’t be good, either.

    Luckily, I have Caddy access logs, and it appears no one ever accessed it.

    So I pulled the secrets out of the Ansible directory and made the repo private, I rotated the credentials, and installed Crowdsec to monitor Caddy access logs and ban bad actors.

    I only noticed the secrets because I had just setup Authelia as an OAuth2 provider for my homelab, and I was adding it to my backup scripts.