3 ms·
Andrew, co-founder of Gitter here. Removing secrets was a lot of work - more than I expected - while we open-sourced the product. I agree with your sentiment
by suprememoocow 9y ago
Andrew, co-founder of Gitter here.
Removing secrets was a lot of work - more than I expected - while we open-sourced the product.
I agree with your sentiment though. Handling secrets in a codebase is not something that it currently easy or standardised.
As an aside, BFG Repo Cleaner really helped a lot with cleaning things up: https://rtyley.github.io/bfg-repo-cleaner/ https://rtyley.github.io/bfg-repo-cleaner/
- StavrosK 9y agoI quite like git-crypt for secrets, I store them in a single place (eg as environment variables) and encrypt that.
- kobeya 9y agoIt's been my impression that the standard (promoted by services like Heroku and Travis) is to pass secrets as environment variables.
- suprememoocow 9y agoFair enough: this is exactly what we've moved to on Gitter on Gitter since open-sourcing the product.