3 ms·
Credentials/tokens go in environment variables. For development, the convention is to make a `.env` file that's in `.gitignore` and load it into your environmen
by _g5q8 5y ago
Credentials/tokens go in environment variables. For development, the convention is to make a `.env` file that's in `.gitignore` and load it into your environment variables. In deployed contexts, you often have a system to do this for you.
- burnished 5y agoWhat sort of tools read .env files/what do I need to know to comfortably set and read environment variables in PowerShell or Bash? Do you just keep the token there in plain text in the .env file? If you have multiple work stations, do you have a method to keep your secrets synched? Sorry about all the questions! I appreciate any insight you might have on this though.
- rgoulter 5y agoOne way I see `.env` files used is with NodeJS webservers which will read in the .env file. But more generally, in shell usage: On Unix machines: direnv https://direnv.net/ https://direnv.net/ (It doesn't support powershell; but I see there are scripts for powershell inspired by this). -- Just be very certain these won't get committed into the repo if you're going to put secrets in them. I think it's preferable to have different secrets for different machines. (e.g. different SSH keys, or different AWS IAM users - which can each assume a shared role if that's easier to manage). If you want to sync secrets, one easy way is to use a password database, and then use Dropbox whatever equivalent solution. Another way would be to use e.g. PGP keys. (The public key of a PGP key can be shared between machines, and can be used to encrypt contents for that machine).
- _g5q8 5y agoThere are projects, like for Node there's a dotenv package, that can load these files. If I have multiple machines, I manually sync them since that's usually the easiest way to manage it as secrets in my experience don't change enough to warrant syncing them.