Skip to content

Expose the secret only during runtime #22

@robin-thomas

Description

@robin-thomas

Rather than exposing the secret during the build stage (sls deploy), figure out a way whereby the secret shall be exposed only during runtime.

Some possible ways:

  1. Replace all instances of process.env.SECRET_ENV_VAR with a shim that connects to AWS Secrets Manager and retrieve the secret during runtime
  2. Encrypts the secret during build stage, and decrypt it during runtime
  3. Inject the secret into code (not safe, since the secret can be determined by anyone who can see the lambda code)

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requesthelp wantedExtra attention is needed

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions