Environment variable
InfrastructureConfiguration supplied from outside your code.
A value handed to your program when it starts, so the same build can point at a test database locally and the real one in production. Where secrets live, because they must never be in code.
See also Secret, Environment
Key rotation
BackendReplacing a secret with a new one.
Issuing a new credential and revoking the old. The first thing to do when a secret leaks: bots scrape public repositories within minutes, so deleting the line changes nothing on its own.
See also Secret, Environment variable
Secret
BackendAny value that grants access.
A database password, an API key, a signing key. Never in code, never in a client bundle. If one leaks, revoke it first. Deleting the line comes second, and git history keeps it regardless.
See also Environment variable, Key rotation