Marco "Ocramius" Pivetta
ocramius.mastodon.social.ap.brid.gy
Marco "Ocramius" Pivetta
@ocramius.mastodon.social.ap.brid.gy
OSS maintainer, Laminas, Mezzio, Roave, previously ZendFramework, Doctrine (ORM) Project.

IT Consultant / software architect for a living.

Daily curse of @nyunyu

[bridged from https://mastodon.social/@ocramius on the fediverse by https://fed.brid.gy/ ]
@kboyd AWS outage
November 7, 2025 at 12:40 AM
@kboyd wasn't there a funeral, a few weeks back?
November 5, 2025 at 5:19 PM
@emd @jclermont an assignment in a conditional? I think not 😜
November 5, 2025 at 1:55 AM
I perhaps found a middle-ground in letting the hypervisor provision the keys to be mounted: it ain't pretty, but it allows me to make the entire provisioning completely declarative, without the private keys leaking out to the provisioner
November 2, 2025 at 3:30 AM
But then... if one has access to the hypervisor, they also have access to the VM disks, and can introspect their keys.

That means that sharing the keys with the hypervisor (or not) makes no difference.

Encrypted disks make no sense in a virtualized environment, since the decryption key would […]
Original post on mastodon.social
mastodon.social
November 2, 2025 at 1:30 AM