3 ms·
> Git should be your only source of truth. Discard any local files or changes, what's not pushed into the repository, does not exist. Completely agree with tha
by myfirstproject 4y ago
> Git should be your only source of truth. Discard any local files or changes, what's not pushed into the repository, does not exist.
Completely agree with that.
- pondidum 4y agoWhat about secrets? I like to do short lived credentials using Vault (e.g. vault can create say db access credentials dynamically), but for things like API keys where I can't do that..? Is the Vault KV store the source of truth?
- rexarex 4y agoWe utilize version control for config/secret management as well…encrypted of course. Edit: now that I think of it, for generated short lived passwords we also use SSM but for anything set by a human it’s in version control…
- lr4444lr 4y agoConfig that should be pushed into the env: it's not code or assets.
- adra 4y agoAt least in cloud providers, they have secret vaults accessible to their customers. The individual secrets are stored in source code but they're encrypted. We've used SOPS as a valuable way to manage these secrets. You can certainly stand up your own secretserver or equiv but may not have all the same.integratuon bells and whistles.
- intelVISA 4y agoGit feat. Nix = no more worries. Ever! Probably.
- lofatdairy 4y agoi think notion uses nix in production. I can't remember what their ci/cd pipeline and version control system is outside of that, or if it was even mentioned in that one comment i saw about it
- f4c39012 4y ago> should Completely agree > only Fine, but can substitute "git" as appropriate > discard any local files or changes Ok for when deployment is completely and always automated, but for that _one special case_ maybe keep a copy of the old that you can revert to until you're _really_ sure of no unwanted effects. In the meantime, find out how & why that local change got made and what can be done to automate it next time