logoalt Hacker News

philboyesterday at 6:28 PM2 repliesview on HN

100% this.

1. Keep secrets in a dedicated secrets store.

2. Read directly from the secrets store in application code. There is no environment, there are no environment variables. Yes, even on local.


Replies

tptacekyesterday at 6:44 PM

It's pretty normal to keep secrets in a dedicated secret store, and then have the service launcher inject them from the secret store into the environment.

show 1 reply
tflintontoday at 1:26 AM

Well you’ll need to know the path in the secret store, so store the path in the environment.