Skip to content

Install script should setup ~/.st2/config with API key so users don't have to renegotiate auth tokens #283

Description

@lakshmi-kannan
No description provided.

Activity

  1. changed the title [-]Install script should export ST2_AUTH_TOKEN at the end to avoid pain and frustration. [/-] [+]Install script should setup ~/.st2/config with API key so users don't have to renegotiate auth tokens[/+] on Apr 22, 2016
  2. Kami commented on May 25, 2016

    @Kami
    Member

    I discussed this with @enykeev on Slack.

    I'm personally not a big fan of shoving API keys in the CLI config - CLI config already solves this problem by allowing user to put credentials (username and password) in the config and handles re-authentication for them.

    API keys are mostly meant for integration with 3rd party services so mixing those with credentials is confusing, imo.

    If we do decide to go with this approach we also need to make it clear which one has the priority (api key or credentials, etc.).

  3. Kami commented on May 25, 2016

    @Kami
    Member

    @lakshmi-kannan Can you please also provide some background and context on this requirement (I'm just wondering why credentials don't solve this already - we already create a default set of credentials in the installer so this requires no additional work...)?

  4. lakshmi-kannan commented on May 25, 2016

    @lakshmi-kannan
    ContributorAuthor

    @Kami Having API key in CLI config is a feature request from customers because they don’t want to put their LDAP or PAM password in config file on a shared box. And having auth token that expires every 24h is not ideal.

  5. Kami commented on May 25, 2016

    @Kami
    Member

    That's for the clarification.

    In this case I'm fine with this feature, I would just think a bit more if [credentials] is the right CLI config section to put it in (and as mentioned above, making sure precedence, etc. works correctly and is documented somewhere).

  6. manasdk commented on May 25, 2016

    @manasdk
    Contributor

    Are we sure about putting in an API key in the cli config by default. I would personally prefer if a user did this intentionally.

    I am +1 to having support for API keys from cli but not to using this option by default.

  7. Kami commented on May 25, 2016

    @Kami
    Member

    That's a good point.

    Especially in that case since it's a custom installation (they use LDAP) I don't see much value for use to generating and API key and putting it in the config automatically (it should be done explicitly by the user).

    I'm fine with putting default credentials in the config though (for convenience) since that's something we need to generate and use by default anyway.

  8. lakshmi-kannan commented on May 25, 2016

    @lakshmi-kannan
    ContributorAuthor

    Are we sure about putting in an API key in the cli config by default. I would personally prefer if a user did this intentionally.

    I don't see the issue but if you guys feel it's somehow less secure, we can just add docs and point to docs at end of install script.

  9. reopened this on Jan 9, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions