ArchitectureSecurity model
Datastore passwords
Ferry generates each datastore password. A service keeps a reference to it, not a copy.
Ferry generates the password of a datastore. It has 32 random characters.
1 / 4
${{datastore.app-db.password}}A reference keeps the password of a datastore in one place. The service stores the reference. It gets the value only in its containers. See Env var references.
The rules
- Ferry generates each password: 32 random characters.
- A password never shows in logs or in error messages.
- A readiness probe never puts a password on a command line.
- The API returns the password to an authenticated caller. See Secrets.
redis-cli gets the password through the environment of the exec: the variable REDISCLI_AUTH.
Each container can reach each datastore by name. Only the password protects a datastore. See What Ferry does not contain.