Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

We can also add a new ACL (ex: "DescribeConfidentialConfigs") or add a new principle (ex: "super.users") to allow to read the confidential configs. It is not good because if some environment grant "all" too some users, and now it'll be able to read confidential configs. The same as applies to super users, it'll get some more extra power nowafter this KIP.