BackendLesson 4 of 48 min

Secrets and environment variables

Where keys live, how they leak, and what to do the moment one does.

A secret is any value that grants access: a database password, an API key, a signing key. The rule is simple to state and easy to break by accident: secrets never go in your code, because your code goes to places you do not fully control.

Instead they are supplied as environment variables, values handed to your program by whatever starts it. The same build then runs against a test database locally and the real one in production, without any code change and without a secret ever sitting in a file you commit.

When a secret leaks
  1. Rotate first
    Issue a new key and revoke the old one. Do this before anything else.
  2. Then clean up
    Remove it from the code. Note that git history keeps it forever, so deleting the line is not enough.
  3. Then check usage
    Look at logs for use you did not make.

Would this value still be dangerous if a stranger read it?

That is the definition of a secret. If yes, it belongs in environment configuration and never in a file you commit or a bundle you ship.

What to remember

  • Secrets come from the environment, never from code.
  • Anything in the client bundle is public forever.
  • On a leak, revoke first; cleaning up history comes second.

Terms in this lesson

Show field notes toggles a search param the loader reads. With it off, the slow promise is never created, so nothing streams.