Map Of Content

Store secrets in a secret manager

Use secret managers or stores for all your secrets. ^[https://www.nodejs-security.com/blog/do-not-use-secrets-in-environment-variables-and-here-is-how-to-do-it-better]

Downsides of storing them in environment:

  • Easily leaked
  • Shared between processes
  • Poorly maneged
  • Not version controlled
  • Leaked from logs
  • Built into docker images