4 ms·
Any good cross-platform and easy ways to share secrets without using environment variables?
by bbkane 1y ago
Any good cross-platform and easy ways to share secrets without using environment variables?
- zdc1 1y agoPoint to a file? E.g. `CONFIG_PATH=/etc/myapp/config.ini /opt/myapp` That being said, I still use env vars and don't plan on stopping. I just haven't (yet?) seen any exploits or threat models relating to it that would keep me up at night.
- maccard 1y agoHow do you get that file? I also use env vars.
- yencabulator 1y agoFor example, systemd or kubernetes. https://systemd.io/CREDENTIALS/ https://systemd.io/CREDENTIALS/ https://kubernetes.io/docs/concepts/configuration/secret/#using-secrets-as-files-from-a-pod https://kubernetes.io/docs/concepts/configuration/secret/#us... (Systemd also has more complex modes that are safer than files. And the Linux kernel has a concept of keyrings that might be even better.)
- deleted 1y ago[deleted]
- bbkane 1y agoIs that file more secure than the environment variables it's replacing? On Linux I think you can secure it to just your service with SELinux. Not sure about Windows
- matthew16550 1y agoSOPS can be part of the solution. It takes care of encrypting and decrypting config files. https://github.com/getsops/sops https://github.com/getsops/sops