Ask HN: How do you manage hard coded passwords and keys in your codebase?
This however is not a good solution. Normally we inject secrets via environment variables, but is there a better way? I heared of secrets management engines, but you also need a shared secret to connect to these two. Do I trade many micro secrets for one big secret than?
Or do I just declare my codebase and the server as secure and announce that if someone has access to these components already owns the company?