3 ms·
The idea is about sharing secrets and keys not locking people out of the codebase. Let's say you are using an OpenAI api key. The only people who can use your
by thoughtlesslabs 9mo ago
The idea is about sharing secrets and keys not locking people out of the codebase.
Let's say you are using an OpenAI api key. The only people who can use your key are the ones you added their public key to the vault.
If you decide they can no longer have access, you change the secret and pull their public key from the repo.
This is no different then if you were sharing secrets in a .env except that they are not stored in plain text which is why you can upload it to github.
If you never give anyone access to the vault they can never use your secrets even if they have the code. They can create their own vaults and keys but they can't use yours.