Safe way to backup env.yml - Serverless FrameworkWhat is the best way to implement “remember me” for a website?Best way to store password in databaseHow safe is it to host sensitive data on repository sites like github, bitbucket, etc.?Dropwizard configuration.yml security issues (where to save and should it contain passwords)Populating Docker containers with sensitive information using kubernetesHow to securely use credentials outside web.config for ASP.NET & AzureBacking up a Serverless Framework deploymentServerless Framework and multiple AWS profiles.NetCore 2.0 secure store credentials in production “on premise” serversHow can I improve the way I'm managing my secret API keys for my NodeJS app that's hosted on Heroku

Is it tax fraud for an individual to declare non-taxable revenue as taxable income? (US tax laws)

Writing rule stating superpower from different root cause is bad writing

Prove that NP is closed under karp reduction?

Why does Kotter return in Welcome Back Kotter?

Fully-Firstable Anagram Sets

TGV timetables / schedules?

Is it important to consider tone, melody, and musical form while writing a song?

If I cast Expeditious Retreat, can I Dash as a bonus action on the same turn?

Have astronauts in space suits ever taken selfies? If so, how?

Is it legal for company to use my work email to pretend I still work there?

How can I prevent hyper evolved versions of regular creatures from wiping out their cousins?

Why doesn't Newton's third law mean a person bounces back to where they started when they hit the ground?

Has the BBC provided arguments for saying Brexit being cancelled is unlikely?

Is it possible to do 50 km distance without any previous training?

Show that if two triangles built on parallel lines, with equal bases have the same perimeter only if they are congruent.

Font hinting is lost in Chrome-like browsers (for some languages )

What are the differences between the usage of 'it' and 'they'?

How much RAM could one put in a typical 80386 setup?

Is this a crack on the carbon frame?

Why don't electron-positron collisions release infinite energy?

Risk of getting Chronic Wasting Disease (CWD) in the United States?

How did the USSR manage to innovate in an environment characterized by government censorship and high bureaucracy?

What is the word for reserving something for yourself before others do?

Why Is Death Allowed In the Matrix?



Safe way to backup env.yml - Serverless Framework


What is the best way to implement “remember me” for a website?Best way to store password in databaseHow safe is it to host sensitive data on repository sites like github, bitbucket, etc.?Dropwizard configuration.yml security issues (where to save and should it contain passwords)Populating Docker containers with sensitive information using kubernetesHow to securely use credentials outside web.config for ASP.NET & AzureBacking up a Serverless Framework deploymentServerless Framework and multiple AWS profiles.NetCore 2.0 secure store credentials in production “on premise” serversHow can I improve the way I'm managing my secret API keys for my NodeJS app that's hosted on Heroku






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








1















It's best practice to put sensitive environment variables into env.yml and reference them in serverless.yml. Of course, this also means not checking env.yml into a code repository.



So where's a safe place to store a backup of env.yml? We have a number of microservices, so we're accumulating several env.yml files for our projects. Even sharing them among devs and keeping them updated can become a bit of an issue - they really could benefit from version control but security trumps convenience so we keep them out of git.



I'd be interested to hear how others manage secrets config in general.










share|improve this question






















  • See serverless.com/blog/serverless-secrets-api-keys

    – Alex
    Mar 9 at 23:05











  • Thank you @Alex! The AWS Parameter Store looks like a real possibility for us.

    – Andrew Goldie
    Mar 10 at 2:36

















1















It's best practice to put sensitive environment variables into env.yml and reference them in serverless.yml. Of course, this also means not checking env.yml into a code repository.



So where's a safe place to store a backup of env.yml? We have a number of microservices, so we're accumulating several env.yml files for our projects. Even sharing them among devs and keeping them updated can become a bit of an issue - they really could benefit from version control but security trumps convenience so we keep them out of git.



I'd be interested to hear how others manage secrets config in general.










share|improve this question






















  • See serverless.com/blog/serverless-secrets-api-keys

    – Alex
    Mar 9 at 23:05











  • Thank you @Alex! The AWS Parameter Store looks like a real possibility for us.

    – Andrew Goldie
    Mar 10 at 2:36













1












1








1








It's best practice to put sensitive environment variables into env.yml and reference them in serverless.yml. Of course, this also means not checking env.yml into a code repository.



So where's a safe place to store a backup of env.yml? We have a number of microservices, so we're accumulating several env.yml files for our projects. Even sharing them among devs and keeping them updated can become a bit of an issue - they really could benefit from version control but security trumps convenience so we keep them out of git.



I'd be interested to hear how others manage secrets config in general.










share|improve this question














It's best practice to put sensitive environment variables into env.yml and reference them in serverless.yml. Of course, this also means not checking env.yml into a code repository.



So where's a safe place to store a backup of env.yml? We have a number of microservices, so we're accumulating several env.yml files for our projects. Even sharing them among devs and keeping them updated can become a bit of an issue - they really could benefit from version control but security trumps convenience so we keep them out of git.



I'd be interested to hear how others manage secrets config in general.







security serverless-framework






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Mar 9 at 2:50









Andrew GoldieAndrew Goldie

165




165












  • See serverless.com/blog/serverless-secrets-api-keys

    – Alex
    Mar 9 at 23:05











  • Thank you @Alex! The AWS Parameter Store looks like a real possibility for us.

    – Andrew Goldie
    Mar 10 at 2:36

















  • See serverless.com/blog/serverless-secrets-api-keys

    – Alex
    Mar 9 at 23:05











  • Thank you @Alex! The AWS Parameter Store looks like a real possibility for us.

    – Andrew Goldie
    Mar 10 at 2:36
















See serverless.com/blog/serverless-secrets-api-keys

– Alex
Mar 9 at 23:05





See serverless.com/blog/serverless-secrets-api-keys

– Alex
Mar 9 at 23:05













Thank you @Alex! The AWS Parameter Store looks like a real possibility for us.

– Andrew Goldie
Mar 10 at 2:36





Thank you @Alex! The AWS Parameter Store looks like a real possibility for us.

– Andrew Goldie
Mar 10 at 2:36












1 Answer
1






active

oldest

votes


















1














While the question was specifically about management of env.yml files, the bigger underlying question is how to manage sensitive environment variables. The link in the comment from Alex is all I needed. Our solution is so AWS-oriented that the AWS Parameter Store is worth exploring.



Alex DeBrie's article



Yan Cui's article on referencing parameter store values at runtime






share|improve this answer

























    Your Answer






    StackExchange.ifUsing("editor", function ()
    StackExchange.using("externalEditor", function ()
    StackExchange.using("snippets", function ()
    StackExchange.snippets.init();
    );
    );
    , "code-snippets");

    StackExchange.ready(function()
    var channelOptions =
    tags: "".split(" "),
    id: "1"
    ;
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function()
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled)
    StackExchange.using("snippets", function()
    createEditor();
    );

    else
    createEditor();

    );

    function createEditor()
    StackExchange.prepareEditor(
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: true,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: 10,
    bindNavPrevention: true,
    postfix: "",
    imageUploader:
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    ,
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    );



    );













    draft saved

    draft discarded


















    StackExchange.ready(
    function ()
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55073549%2fsafe-way-to-backup-env-yml-serverless-framework%23new-answer', 'question_page');

    );

    Post as a guest















    Required, but never shown

























    1 Answer
    1






    active

    oldest

    votes








    1 Answer
    1






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    1














    While the question was specifically about management of env.yml files, the bigger underlying question is how to manage sensitive environment variables. The link in the comment from Alex is all I needed. Our solution is so AWS-oriented that the AWS Parameter Store is worth exploring.



    Alex DeBrie's article



    Yan Cui's article on referencing parameter store values at runtime






    share|improve this answer





























      1














      While the question was specifically about management of env.yml files, the bigger underlying question is how to manage sensitive environment variables. The link in the comment from Alex is all I needed. Our solution is so AWS-oriented that the AWS Parameter Store is worth exploring.



      Alex DeBrie's article



      Yan Cui's article on referencing parameter store values at runtime






      share|improve this answer



























        1












        1








        1







        While the question was specifically about management of env.yml files, the bigger underlying question is how to manage sensitive environment variables. The link in the comment from Alex is all I needed. Our solution is so AWS-oriented that the AWS Parameter Store is worth exploring.



        Alex DeBrie's article



        Yan Cui's article on referencing parameter store values at runtime






        share|improve this answer















        While the question was specifically about management of env.yml files, the bigger underlying question is how to manage sensitive environment variables. The link in the comment from Alex is all I needed. Our solution is so AWS-oriented that the AWS Parameter Store is worth exploring.



        Alex DeBrie's article



        Yan Cui's article on referencing parameter store values at runtime







        share|improve this answer














        share|improve this answer



        share|improve this answer








        edited Mar 10 at 11:59

























        answered Mar 10 at 2:41









        Andrew GoldieAndrew Goldie

        165




        165





























            draft saved

            draft discarded
















































            Thanks for contributing an answer to Stack Overflow!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid


            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.

            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55073549%2fsafe-way-to-backup-env-yml-serverless-framework%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            Popular posts from this blog

            Identity Server 4 is not redirecting to Angular app after login2019 Community Moderator ElectionIdentity Server 4 and dockerIdentityserver implicit flow unauthorized_clientIdentityServer Hybrid Flow - Access Token is null after user successful loginIdentity Server to MVC client : Page Redirect After loginLogin with Steam OpenId(oidc-client-js)Identity Server 4+.NET Core 2.0 + IdentityIdentityServer4 post-login redirect not working in Edge browserCall to IdentityServer4 generates System.NullReferenceException: Object reference not set to an instance of an objectIdentityServer4 without HTTPS not workingHow to get Authorization code from identity server without login form

            2005 Ahvaz unrest Contents Background Causes Casualties Aftermath See also References Navigation menue"At Least 10 Are Killed by Bombs in Iran""Iran"Archived"Arab-Iranians in Iran to make April 15 'Day of Fury'"State of Mind, State of Order: Reactions to Ethnic Unrest in the Islamic Republic of Iran.10.1111/j.1754-9469.2008.00028.x"Iran hangs Arab separatists"Iran Overview from ArchivedConstitution of the Islamic Republic of Iran"Tehran puzzled by forged 'riots' letter""Iran and its minorities: Down in the second class""Iran: Handling Of Ahvaz Unrest Could End With Televised Confessions""Bombings Rock Iran Ahead of Election""Five die in Iran ethnic clashes""Iran: Need for restraint as anniversary of unrest in Khuzestan approaches"Archived"Iranian Sunni protesters killed in clashes with security forces"Archived

            Can't initialize raids on a new ASUS Prime B360M-A motherboard2019 Community Moderator ElectionSimilar to RAID config yet more like mirroring solution?Can't get motherboard serial numberWhy does the BIOS entry point start with a WBINVD instruction?UEFI performance Asus Maximus V Extreme