Why AWS access and secret keys should not be in the codebase
advancedweb.hu
advancedweb.hu
const client = new DocumentClient({
region: process.env.REGION,
accessKeyId: process.env.ACCESS_KEY_ID,
secretAccessKey: process.env.SECRET_ACCESS_KEY
});
Is this still a bad practice?You don’t need your credentials anywhere near your code.
Every AWS SDK that I’m aware of, let’s you new up your client with no parameters.
Your credentials should be in your user directory set by “aws configure” locally. When running on AWS, the SDK will automatically get your credentials based on the role attached to your EC2 instance or lambda.
curl http://169.254.169.254/latest/meta-data/iam/security-credentials
But of course, you still shouldn't specify them in your code.When you’re developing locally they should be in your user directory and configured via the CLI (far away from your git repo) and when running on AWS, you should be using the attached profile. Either way, when you new up the client, the SDK will find them automatically.
A coworker pushed my passport details to a (private) github repository. Still freaking out about it, considering there's some sort of garbage collection, which keeps deleted items around for an undefined amount of time :|