logoalt Hacker News

XCSmetoday at 9:13 AM1 replyview on HN

But how do you do that without also having a long-lived key or access token to those services?


Replies

noAnswertoday at 12:39 PM

The long-lived credentials life inside a stripped down machine. Cron/lego/Ansible handles the renewal. The machines on the edge can't renew their keys themselves.

show 1 reply