idea- what if we encrypted .env files with the same cryptographic credentials that prove you have git commit rights? They still shouldn't be checked into git, but it only takes one mistake to accidentally check them in. (and the encrypt + check in solution is vulnerable to offline cracking and key leaks, i.e. an infinite regress problem of a key to get a key to get a key to get a key...)
Post
July 27, 2024