The skill says drawings carry names and sentences go in <desc> and the paragraph beside the figure. I put sentences in node details and edge labels instead, and 27 of the 28 diagrams shipped with prose inside the canvas — "예측 다섯 개가 틀렸다", "아홉 번 조용히 실패했다", "막혀서 닿지 않는다". Only label and details render on the canvas; description does not. So every sentence moved to a noun phrase and the meaning stays in description, which was already carrying it. 막혀서 닿지 않는다 -> 차단 아홉 번 조용히 실패했다 -> 조용한 실패 9건 예측 다섯 개가 틀렸다 -> 틀린 예측 5건 로그아웃이 정리하지 않는다 -> 로그아웃 미정리 볼륨이 없으면 여기까지다 -> 볼륨 없음 Three node labels were sentences too and became names: 세션 스냅샷, 예측 선기록, 대조군 확보. What stays is what the rules protect — identifiers, commands and measured values: PRIMARY KEY (client_registration_id, principal_name), ValidationFailedException: 1 changesets check sum, nginx -t && nginx -s reload, SET LOCAL synchronous_commit TO OFF. Those are names of things, not prose about them. 294 canvas strings across 28 diagrams, none matching a sentence ending, average 11 characters. All 28 still lint clean and re-rendered. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
21 lines
880 B
Markdown
21 lines
880 B
Markdown
# base64 는 암호화가 아니다
|
||
|
||
## Alternative text
|
||
|
||
Secret 의 값이 base64 디코드와 파드 환경 변수 두 경로로 모두 평문에 닿는 구성.
|
||
|
||
## Long description
|
||
|
||
kubectl get secret -o yaml 이 보여주는 base64 는 인코딩이지 암호화가 아니다. etcd 에 평문으로 있다. 그리고 파드 안에서 env 를 grep 하면 그대로 나온다. 값을 Secret 에 넣었다는 것과 값이 가려졌다는 것은 다른 사건이다.
|
||
|
||
## Elements and evidence
|
||
|
||
- **k8s Secret** (datastore): base64 로 담긴다. Evidence: L495–L501.
|
||
- **etcd** (datastore): 평문으로 있다. Evidence: L495–L501.
|
||
- **파드 환경 변수** (component): env 로 그대로 읽힌다. Evidence: L495–L501.
|
||
|
||
## Relationships
|
||
|
||
- **k8s Secret → etcd:** 저장. Evidence: L495–L501.
|
||
- **k8s Secret → 파드 환경 변수:** 주입. Evidence: L495–L501.
|