Repository navigation
security: document and purge leaked DigitalOcean Spaces keys from history - #328
Open
arnoldcastro5000 wants to merge 1 commit into
Open
arnoldcastro5000 wants to merge 1 commit into
arnoldcastro5000 wants to merge 1 commit into
Conversation
arnoldcastro5000
force-pushed
the
security/purge-spaces-keys
branch
from
September 11, 2026 14:26
8cd8cb4 to
c1df27f
Compare
arnoldcastro5000
marked this pull request as ready for review
September 11, 2026 14:27
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this PR does
The leaked keys are already gone from the current files. Someone deleted
kubernetes/terraform/environments/variable.tfin 2021 (commit1e87d66). But the keys still live in the git history, from commitbbff87eonward. So there is nothing to change in the current code. This PR adds a short security note that records the required history purge.This PR is step 1 of 2. It documents the work. It does not remove the keys from the history. A maintainer with admin rights must do step 2. The commands are below. You can copy and paste them.
Why
The file
kubernetes/terraform/environments/variable.tfhardcoded a DigitalOcean Spacesaccess_keyandsecret_key. A public repository shows the full history to everyone, so the keys are still reachable by commit SHA and in forks.The keys are already rotated. The old values no longer work. This purge removes the dead values from GitHub.
What changed here
docs/security/history-purge-runbook.mdwith the step-2 instructions below.No source or Terraform file changes. The tip already has no secret. Only
variable.tfever held keys; the other files in commitbbff87e(main.tf,dev.env.tfvars,outputs.tf) are clean.Step 2 — history purge (maintainer with admin only)
The keys sit in the history from
bbff87e(2021-04-29) to1e87d66^. This repository has no tags. You must rewrite the history and force-push.Requirements on your machine:
git(2.24 or newer),python3, andcurl. You do not need to installgit-filter-repo; Block 1 downloads it.Run the blocks in order, in one terminal session.
Block 1 — redact and verify locally (safe; does not push)
This block finds the key values itself and replaces every copy with
REDACTED. You do not paste any secret.Manual gate A — lift branch protection
Lift the branch protection on
masterin the GitHub UI (Settings → Branches), or with your admin token. Record the current rules first, so you can restore them. A protected branch rejects the force-push.Block 2 — push the rewrite
Manual gate B — restore branch protection
Restore the branch protection on
masterwith the same rules you recorded in gate A.Block 3 — verify on a fresh clone (done-bar)
Verification trap to avoid: do not use
git clone --mirrorto verify. It fetches therefs/pull/*refs, which you cannot change, so it always shows a key and reports a false failure.Close the open pull requests. This repository has 14 open PRs. A rewrite changes every commit SHA, so their bases become invalid even though none touch
variable.tf. Close them and ask the authors to re-create against the rewritten base. After the push, tell contributors to re-clone or rungit reset --hard.Step 3 — residual exposure (maintainer with admin only; manual)
GitHub keeps old commits alive in three places you cannot reach with a push: the
refs/pull/*refs (about 138 pull requests, open and closed), the cached commit views, and the ~30 forks. The keys are dead, but do the best-effort cleanup:refs/pull/*/headcopies of the keys, to purge the cached commit views, and to remove the dangling commits from the shared fork-network storage.Scope
.gitignorefor*.tfvars, config templates) is out of scope. Note: an open PR (fix: expand .gitignore to cover all .tfvars files #295) already expands.gitignorefor.tfvarsfiles.