logoalt Hacker News

Stop Putting Secrets in .env Files

17 pointsby veverkaptoday at 12:53 AM5 commentsview on HN

Comments

mahaekohtoday at 6:33 AM

Mfw typing the command stores the password in plaintext in my shell history

theozerotoday at 4:41 AM

You will probably really like https://varlock.dev

It’s a whole toolkit for this - with built in validation, type safety, and extra protection for sensitive secrets.

thedentoday at 4:19 AM

So the solution is to use a proprietary password manager instead? No thanks

show 1 reply
hebetudetoday at 4:54 AM

People still code on their local boxes? op is not biometric secured over an ssh tunnel