Safe way to backup env.yml - Serverless Framework Announcing the arrival of Valued Associate #679: Cesar Manara Planned maintenance scheduled April 23, 2019 at 23:30 UTC (7:30pm US/Eastern) Data science time! April 2019 and salary with experience The Ask Question Wizard is Live!What is the best way to implement “remember me” for a website?Best way to store password in databaseHow safe is it to host sensitive data on repository sites like github, bitbucket, etc.?Dropwizard configuration.yml security issues (where to save and should it contain passwords)Populating Docker containers with sensitive information using kubernetesHow to securely use credentials outside web.config for ASP.NET & AzureBacking up a Serverless Framework deploymentServerless Framework and multiple AWS profiles.NetCore 2.0 secure store credentials in production “on premise” serversHow can I improve the way I'm managing my secret API keys for my NodeJS app that's hosted on Heroku

How do I deal with an erroneously large refund?

Kepler's 3rd law: ratios don't fit data

What's the connection between Mr. Nancy and fried chicken?

Married in secret, can marital status in passport be changed at a later date?

Why does BitLocker not use RSA?

Can this water damage be explained by lack of gutters and grading issues?

How to make an animal which can only breed for a certain number of generations?

Does Prince Arnaud cause someone holding the Princess to lose?

How is an IPA symbol that lacks a name (e.g. ɲ) called?

How to ask rejected full-time candidates to apply to teach individual courses?

Pointing to problems without suggesting solutions

Is the Mordenkainen's Sword spell underpowered?

When does Bran Stark remember Jamie pushing him?

How to mute a string and play another at the same time

Protagonist's race is hidden - should I reveal it?

What is the difference between 准时 and 按时?

lm and glm function in R

Providing direct feedback to a product salesperson

Can gravitational waves pass through a black hole?

Meaning of this sentence, confused by まで

Marquee sign letters

If gravity precedes the formation of a solar system, where did the mass come from that caused the gravity?

Assertions In A Mock Callout Test

How to produce a PS1 prompt in bash or ksh93 similar to tcsh



Safe way to backup env.yml - Serverless Framework



Announcing the arrival of Valued Associate #679: Cesar Manara
Planned maintenance scheduled April 23, 2019 at 23:30 UTC (7:30pm US/Eastern)
Data science time! April 2019 and salary with experience
The Ask Question Wizard is Live!What is the best way to implement “remember me” for a website?Best way to store password in databaseHow safe is it to host sensitive data on repository sites like github, bitbucket, etc.?Dropwizard configuration.yml security issues (where to save and should it contain passwords)Populating Docker containers with sensitive information using kubernetesHow to securely use credentials outside web.config for ASP.NET & AzureBacking up a Serverless Framework deploymentServerless Framework and multiple AWS profiles.NetCore 2.0 secure store credentials in production “on premise” serversHow can I improve the way I'm managing my secret API keys for my NodeJS app that's hosted on Heroku



.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








1















It's best practice to put sensitive environment variables into env.yml and reference them in serverless.yml. Of course, this also means not checking env.yml into a code repository.



So where's a safe place to store a backup of env.yml? We have a number of microservices, so we're accumulating several env.yml files for our projects. Even sharing them among devs and keeping them updated can become a bit of an issue - they really could benefit from version control but security trumps convenience so we keep them out of git.



I'd be interested to hear how others manage secrets config in general.










share|improve this question






















  • See serverless.com/blog/serverless-secrets-api-keys

    – Alex
    Mar 9 at 23:05











  • Thank you @Alex! The AWS Parameter Store looks like a real possibility for us.

    – Andrew Goldie
    Mar 10 at 2:36

















1















It's best practice to put sensitive environment variables into env.yml and reference them in serverless.yml. Of course, this also means not checking env.yml into a code repository.



So where's a safe place to store a backup of env.yml? We have a number of microservices, so we're accumulating several env.yml files for our projects. Even sharing them among devs and keeping them updated can become a bit of an issue - they really could benefit from version control but security trumps convenience so we keep them out of git.



I'd be interested to hear how others manage secrets config in general.










share|improve this question






















  • See serverless.com/blog/serverless-secrets-api-keys

    – Alex
    Mar 9 at 23:05











  • Thank you @Alex! The AWS Parameter Store looks like a real possibility for us.

    – Andrew Goldie
    Mar 10 at 2:36













1












1








1








It's best practice to put sensitive environment variables into env.yml and reference them in serverless.yml. Of course, this also means not checking env.yml into a code repository.



So where's a safe place to store a backup of env.yml? We have a number of microservices, so we're accumulating several env.yml files for our projects. Even sharing them among devs and keeping them updated can become a bit of an issue - they really could benefit from version control but security trumps convenience so we keep them out of git.



I'd be interested to hear how others manage secrets config in general.










share|improve this question














It's best practice to put sensitive environment variables into env.yml and reference them in serverless.yml. Of course, this also means not checking env.yml into a code repository.



So where's a safe place to store a backup of env.yml? We have a number of microservices, so we're accumulating several env.yml files for our projects. Even sharing them among devs and keeping them updated can become a bit of an issue - they really could benefit from version control but security trumps convenience so we keep them out of git.



I'd be interested to hear how others manage secrets config in general.







security serverless-framework






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Mar 9 at 2:50









Andrew GoldieAndrew Goldie

165




165












  • See serverless.com/blog/serverless-secrets-api-keys

    – Alex
    Mar 9 at 23:05











  • Thank you @Alex! The AWS Parameter Store looks like a real possibility for us.

    – Andrew Goldie
    Mar 10 at 2:36

















  • See serverless.com/blog/serverless-secrets-api-keys

    – Alex
    Mar 9 at 23:05











  • Thank you @Alex! The AWS Parameter Store looks like a real possibility for us.

    – Andrew Goldie
    Mar 10 at 2:36
















See serverless.com/blog/serverless-secrets-api-keys

– Alex
Mar 9 at 23:05





See serverless.com/blog/serverless-secrets-api-keys

– Alex
Mar 9 at 23:05













Thank you @Alex! The AWS Parameter Store looks like a real possibility for us.

– Andrew Goldie
Mar 10 at 2:36





Thank you @Alex! The AWS Parameter Store looks like a real possibility for us.

– Andrew Goldie
Mar 10 at 2:36












1 Answer
1






active

oldest

votes


















1














While the question was specifically about management of env.yml files, the bigger underlying question is how to manage sensitive environment variables. The link in the comment from Alex is all I needed. Our solution is so AWS-oriented that the AWS Parameter Store is worth exploring.



Alex DeBrie's article



Yan Cui's article on referencing parameter store values at runtime






share|improve this answer

























    Your Answer






    StackExchange.ifUsing("editor", function ()
    StackExchange.using("externalEditor", function ()
    StackExchange.using("snippets", function ()
    StackExchange.snippets.init();
    );
    );
    , "code-snippets");

    StackExchange.ready(function()
    var channelOptions =
    tags: "".split(" "),
    id: "1"
    ;
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function()
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled)
    StackExchange.using("snippets", function()
    createEditor();
    );

    else
    createEditor();

    );

    function createEditor()
    StackExchange.prepareEditor(
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: true,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: 10,
    bindNavPrevention: true,
    postfix: "",
    imageUploader:
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    ,
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    );



    );













    draft saved

    draft discarded


















    StackExchange.ready(
    function ()
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55073549%2fsafe-way-to-backup-env-yml-serverless-framework%23new-answer', 'question_page');

    );

    Post as a guest















    Required, but never shown

























    1 Answer
    1






    active

    oldest

    votes








    1 Answer
    1






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    1














    While the question was specifically about management of env.yml files, the bigger underlying question is how to manage sensitive environment variables. The link in the comment from Alex is all I needed. Our solution is so AWS-oriented that the AWS Parameter Store is worth exploring.



    Alex DeBrie's article



    Yan Cui's article on referencing parameter store values at runtime






    share|improve this answer





























      1














      While the question was specifically about management of env.yml files, the bigger underlying question is how to manage sensitive environment variables. The link in the comment from Alex is all I needed. Our solution is so AWS-oriented that the AWS Parameter Store is worth exploring.



      Alex DeBrie's article



      Yan Cui's article on referencing parameter store values at runtime






      share|improve this answer



























        1












        1








        1







        While the question was specifically about management of env.yml files, the bigger underlying question is how to manage sensitive environment variables. The link in the comment from Alex is all I needed. Our solution is so AWS-oriented that the AWS Parameter Store is worth exploring.



        Alex DeBrie's article



        Yan Cui's article on referencing parameter store values at runtime






        share|improve this answer















        While the question was specifically about management of env.yml files, the bigger underlying question is how to manage sensitive environment variables. The link in the comment from Alex is all I needed. Our solution is so AWS-oriented that the AWS Parameter Store is worth exploring.



        Alex DeBrie's article



        Yan Cui's article on referencing parameter store values at runtime







        share|improve this answer














        share|improve this answer



        share|improve this answer








        edited Mar 10 at 11:59

























        answered Mar 10 at 2:41









        Andrew GoldieAndrew Goldie

        165




        165





























            draft saved

            draft discarded
















































            Thanks for contributing an answer to Stack Overflow!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid


            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.

            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55073549%2fsafe-way-to-backup-env-yml-serverless-framework%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            Popular posts from this blog

            Save data to MySQL database using ExtJS and PHP [closed]2019 Community Moderator ElectionHow can I prevent SQL injection in PHP?Which MySQL data type to use for storing boolean valuesPHP: Delete an element from an arrayHow do I connect to a MySQL Database in Python?Should I use the datetime or timestamp data type in MySQL?How to get a list of MySQL user accountsHow Do You Parse and Process HTML/XML in PHP?Reference — What does this symbol mean in PHP?How does PHP 'foreach' actually work?Why shouldn't I use mysql_* functions in PHP?

            Compiling GNU Global with universal-ctags support Announcing the arrival of Valued Associate #679: Cesar Manara Planned maintenance scheduled April 23, 2019 at 23:30 UTC (7:30pm US/Eastern) Data science time! April 2019 and salary with experience The Ask Question Wizard is Live!Tags for Emacs: Relationship between etags, ebrowse, cscope, GNU Global and exuberant ctagsVim and Ctags tips and trickscscope or ctags why choose one over the other?scons and ctagsctags cannot open option file “.ctags”Adding tag scopes in universal-ctagsShould I use Universal-ctags?Universal ctags on WindowsHow do I install GNU Global with universal ctags support using Homebrew?Universal ctags with emacsHow to highlight ctags generated by Universal Ctags in Vim?

            Add ONERROR event to image from jsp tldHow to add an image to a JPanel?Saving image from PHP URLHTML img scalingCheck if an image is loaded (no errors) with jQueryHow to force an <img> to take up width, even if the image is not loadedHow do I populate hidden form field with a value set in Spring ControllerStyling Raw elements Generated from JSP tagds with Jquery MobileLimit resizing of images with explicitly set width and height attributeserror TLD use in a jsp fileJsp tld files cannot be resolved