Back
Post
Posted

How do you secure stuff like .env secrets.yml that have important keys and token away from contractors who are working for you?



There needs to be a level of trust when working with contractors. Apart from that you can create separate keys for contractors or set up the app in such a way that it still works without having all the keys in place. (Automatically disable functionality reliant on keys.)

Or generate new keys after the contract ends.

Home
Search
Messages
Notifications
More

Are you sure?