-
-
Notifications
You must be signed in to change notification settings - Fork 6
Description
With the new setup using an encrypted db, we open up the possibility of creating an ephemeral container.
What this means is, if people want more security instead of convenience, they can chose an ephemeral container, then the db and key will live in memory and never touch the disk, never saving the sensitive information and credentials to disk at all.
This comes with the tradeoff that on every container restart, you need to re-do the setup.
Then the persistent is how it is right now, you can mount the db/key volume and let it persist. Although it is less secure, it is more convenient.
This will give users the option to chose if they want convenience or security, and makes our tool more flexible while keeping the core philosophy intact.
If someone has ideas for/about this, please let me know.