logoalt Hacker News

fragmedeyesterday at 8:00 PM1 replyview on HN

I haven't solved the problem of sensitive .env files sitting around on my computer.


Replies

spacemuleyesterday at 8:23 PM

`sops exec-env`

I have an alias set for when I'm working with opentofu:

`alias tfenter='sops exec-env secrets.yaml "/bin/bash"'`

I encrypt with openbao's transit engine and backup age key kept in a password manager, so no secrets live on disk.