> ... reads a file in secrets.yml format and injects secrets as environment variables into any process
Meaning that every child process will subsequently have access to the secrets?
Meaning that every child process will subsequently have access to the secrets?
It seems that this is designed to protect you from untrusted execution environments, which I don't see as feasible. What am I missing?
Shared web hosting where you share a physical machine with other users. Not everyone is into the VM craze these days, thank god
ps auxwwe
on Linux, Mac OS X, and other Unix-en will show all processes for all users with their complete environment.Environment variables should not be used to share secrets.