Comment 1 for bug 1403617

Revision history for this message
Dan Watkins (oddbloke) wrote :

We need to decide how we're going to handle this.

The GCE tooling (and therefore documentation) suggest that if instance-level keys are supplied, then project-level keys are disregarded. Do we want to mirror this?

I'm torn on this one. On the one hand, we already don't match the GCE docs in the way we handle project-level keys so this may be a foolish consistency. On the other hand, this is making our images even more distinct from the GCE standards which is a Bad Thing (TM).

Also, if people are relying on setting instance-level SSH keys to exclude project-level SSH keys, then not mirroring the GCE tooling might make instances unexpectedly insecure.