
A container identity bootstrapping tool
7/3/2017
Introduced PAL (Permissive Action Link), a tool for securely distributing secrets to Dockerized production applications. PAL enables encrypted secrets to be decrypted at runtime after service identity is established, supporting PGP and Red October encryption methods. It uses container labels derived from cgroups and Docker metadata for authorization, allowing secrets to be installed as environment variables or files within containers.