3 ms·
> Don't use secrets in environment variables, but use this secret in environment variables, but this one gives you access to all secrets. Not much use to an at
by bogantech 2y ago
> Don't use secrets in environment variables, but use this secret in environment variables, but this one gives you access to all secrets.
Not much use to an attacker if the token / approle is restricted to a specific IP / EC2 instance id.
Auditable too
- mbrumlow 2y agoMaybe all your secrets should be node locked …