Joe M
06/03/2024, 10:36 PMOz Katz
_lakefs_actions/
would then be able to perform any action this IAM principal is allowed to do. This is a privilege escalation.
I agree hard coding secrets in a yaml file in a repo isn't great - we do plan on supporting a secrets management API for hooks, similar to the one provided by GitHub and other similar services.