Environment variables are not secret vaults
Putting a secret in an environment variable keeps it out of the code, which is an improvement, and it is not a vault.
They leak readily: into crash reports, into debug output, into process listings, into logs that capture the whole environment for troubleshooting, into child processes nobody thought about. They also cannot be rotated without a restart and leave no record of who read them. It is a reasonable step up from hardcoding. It is not the destination.
More on Passwords and secrets
- Password length beats decorative complexityAdd wheels, not squiggles
- Forced rotation can create predictable passwordsOnly one character moves
- Salts make identical passwords look differentOne grain each
- Every secret copy creates another secret to protectEvery copy needs its own guard
- Secrets in source control have a long memoryThe deletion is just another commit
- Temporary credentials shrink the theft windowSame theft, different window
