3 ms·
A good key rotation scheme and separate API keys for different purposes. Precommit automated checks for secrets.
by solotronics 6y ago
A good key rotation scheme and separate API keys for different purposes. Precommit automated checks for secrets.
- john-tells-all 6y agoAbsolutely! - a good, tested key rotation practice will reduce the impact of any accidental exposures. It'll also help tremendously when staff changes, and you can do things like "rotate all keys every quarter" - separate API keys for different services and environments means that even if your staging network-layer key is exposed, it can't affect your staging database (= data), nor your production database (= critical data). - I've used "search for AWS secrets" as a pre-commit and also CI hook with great luck. I've even accidentally added a secret myself :) but with the checks the error was immediately found. No problems!