Skip to content

Harden SPIRE networking and deployment secret storage #32

Description

The prototype still carries infrastructure hardening gaps, including broad SPIRE VM ingress and sensitive bootstrap/configuration values in environment variables.

Acceptance criteria:

  • Restrict SPIRE server ports to required VNet/subnet sources.
  • Inventory sensitive Container App and azd values.
  • Move long-lived secrets and trust material to Key Vault-backed storage where supported.
  • Document rotation and emergency recovery.
  • Verify full deployment and re-attestation after hardening.

Relevant files:

  • infra/modules/spire-server-vm.bicep
  • deploy.sh
  • docs/runbooks/hard-won-learnings.md

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:deploymentAzure deployment and lifecyclearea:spiffeSPIFFE and SPIRE runtimepriority:P1Prototype hardening prioritysecuritySecurity hardening

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions