4 ms·
There is a business opportunity here. Managing credentials and secrets is (passwords, private certs, etc) is hard. Making that process turnkey, secure and easy
by jbeda 16y ago
There is a business opportunity here. Managing credentials and secrets is (passwords, private certs, etc) is hard. Making that process turnkey, secure and easy would be useful.
- thenduks 16y agoI'm not sure it's that hard. You can use any number of very low-barrier strategies to solve this. One that was mentioned a few times in this thread is to use environment variables. Personally I just put a {whatever}.yml or similar in my project tree somewhere and throw it in .gitignore. I can't imagine a process that starts with "go to westorecredentials.com and sign up..." being any easier. Willing to be surprised :)
- fragmede 16y agoPeople are advocating not saving settings to source control. F-that, I want to be able to clone my repo and run the project without scp-ing an additional file around. A file, that by all rights should be part of the project. Here's my solution - github 'extends' git somehow, so files can be marked private. Then, unless you have commit rights to that repo, you can't see the file's contents. So a public http checkouts lacks the secret password. And because it's git, someone you give commit rights to is someone you trust. People you don't trust can just make their own repo.
- thenduks 16y agoThat sounds like too much software to me. What's with the aversion to scp? You only have to do it once per box you set up... There's something to be said for having GitHub do everything 1000% for you, but there's also something to the unix philosophy that would suggest git is good at the version control thing, and scp is good for the configuration-file-moving thing.
- fragmede 16y agoso... which version of the config file are you using?
- thenduks 16y agoThe one listed first in a `git log config/whatever.yml` Just because it isn't in a public repo on GitHub doesn't mean it isn't versioned properly. Quite the contrary, I use git locally and on a personal webserver for tons of stuff. The point isn't that it shouldn't go into git. It's that it doesn't belong as part of your project. Different config options are often needed on each machine, especially development boxes. I don't have the same database.yml as my co-workers... I have my box in production mode or with memcache off for testing purposes maybe... There's tons of stuff like that. I still keep those files (along with my ~/.git/config, ~/.ssh/config, .gemrc, ~/.profile, ~/.vim* and a hundred other things) in git, just not on GitHub in a public repo.