The conclusions here feel wrong to me. The two lessons I see are: 1. Don't run agents anywhere they might be able to access production environment credentials – it's on you to know which credentials those are 2. Keep tested backups that are independent from your production host
Agent Security: Protecting Production Credentials and Backups
By
–
