4 ms·
Are you familiar with the recent Mercedes-Benz Source Code Exposure [1]? It's a good example of why you should consider a secrets manager for any serious projec
by AlwaysNewb23 3y ago
Are you familiar with the recent Mercedes-Benz Source Code Exposure [1]? It's a good example of why you should consider a secrets manager for any serious project. Environment variables come with a lot of risks and are difficult to manage as teams grow. 1) ENV files are easy to accidentally push to a repo. 2) It's easy for environment variables to get out of sync among developers. 3) In the case of exposure, it's often difficult to rotate secrets quickly. A secrets manager removes this risk - but you do need to trust whatever service you decide to use, as well as make sure it's compatible with your infrastructure/cloud environment.
[1] https://www.doppler.com/blog/lessons-from-mercedes-benz-source-code-exposure https://www.doppler.com/blog/lessons-from-mercedes-benz-sour...)
- AlwaysNewb23 3y agoFor personal projects, it's probably fine to just use environmental variables and .env files the traditional way. The security risk really increases when you start to scale and work with other team members.
- tester457 3y agoThank you for your answers, they were very helpful. When the Mercedes-Benz Source Code Exposure happened I remembered I wasn't doing secrets management in the proper way, but good to know there's less risk since I'm a solo developer. But Doppler looks worth a shot.