3 ms·
Is this a very roundabout way to do a wrapper shell script (the target audience being people who cannot write shell scripts)? $ cat > secrets && chmod 600
by rdancer 11y ago
Is this a very roundabout way to do a wrapper shell script (the target audience being people who cannot write shell scripts)?
$ cat > secrets && chmod 600 secrets
export SECRET_1='Jerry is a mushroom'
export SECRET_2='Jessica'\''s a chicken!'
$ cat > wrapper && chmod +x wrapper
#!/bin/sh
set -e
. ./secrets
exec "$@"
$ env -i ./wrapper env
SECRET_1=Jerry is a mushroom
SECRET_2=Jessica's a chicken!
PWD=/home/rdancer
- gingerlime 11y agoI do appreciate the simplicity (and effectiveness) of this wrapper, and I would definitely recommend this much simpler approach over a more robust tool in many situations. I think the added value (and increased complexity) from tools like this is that allow you to store your secrets not only on the filesystem, but also in various (typically external) vaults. Some also provide more granular access control to only a subset of secrets, revocation and so on.
- tedmiston 11y agoThat works until you have a multi-person dev team that wants to securely exchange and retrieve secrets without storing them in the repo. For example, S3 credentials, or the API secret to an external service (that may have been rotated since the last time you pulled).