This might sound very obvious, and it is, but there are so many horror stories of people being charged tens of thousands of dollars because they accidentally pushed their secret keys to GitHub or any other public repository hubs, which are being scanned constantly for such credentials.