4 ms·
I don't think storing passwords in any format in source control is good. Like someone else said, it's mixing app logic with deployment. We use a combination of
by wuster 14y ago
I don't think storing passwords in any format in source control is good. Like someone else said, it's mixing app logic with deployment.
We use a combination of Google's open source Keyczar [1] and a relatively new Python keyring [2] library which uses the Keyczar crypter to read/write keys to a keyring storage backend, where the backend interface can be implemented with local crypted files or a cloud service.
[1] http://www.keyczar.org/ http://www.keyczar.org/
[2] http://pypi.python.org/pypi/keyring http://pypi.python.org/pypi/keyring
We built this Python wrapper called appauth around of the concept of a Keyring service by application domain.
e.g. pseudo code:
import appauth
auth_service = appauth.AuthService('my-web-app')
db_creds_cfg = auth_service.get('primary-db')
Inside of db_creds_cfg, it can be a free-form dictionary that provides whatever details is needed to get into a resource:
db_creds_cfg['db_host']
db_creds_cfg['db_port']
db_creds_cfg['username']
db_creds_cfg['password']
I put in some honest effort to find an open source solution to this, but failed to find anything with a simple install process AND programming interface. Is there any interest from HN if we choose to open source this?
Furthermore, we use Google Authenticator on our servers to require two-factor auth: http://code.google.com/p/google-authenticator/ http://code.google.com/p/google-authenticator/, on top of disabling password auth in favor of signing in with ssh keys. All log files are then either set to permission 600 just to be super paranoid.
- RegEx 14y ago> Is there any interest from HN if we choose to open source this? I personally don't understand this type of comment. Just open source it!
- wuster 14y agogotta go through the motions of putting up good readmes and documentation, not a trivial amount of effort, only worth it if I think enough people want it. open sourcing something isn't exactly free effort.
- RegEx 14y agoA project is worth open sourcing if it's useful enough for other people to use. I personally do not believe there's much more to it than that.
- Argorak 14y agoThat sound like a generalization of things like: http://www.postgresql.org/docs/9.0/static/libpq-pgservice.html http://www.postgresql.org/docs/9.0/static/libpq-pgservice.ht...
- Emouri 14y agoI'd find something like that useful. Don't know if that counts as interest from HN though