if strings.Contains(dbname, "prod") {
panic("Refusing to wipe production database!")
}
Truncate(db) if strings.Contains(dbname, "prod") {
panic("Refusing to wipe production database!")
}
Truncate(db)*ideally* devs should not have prod access or their credentials should only have limited access without permissions for destructive actions like drop/truncate etc.
But in reality, there's always that one helpful dba/dev who shares admin credentials for a quick prod fix with someone and then those credentials end up in a wiki somewhere as part of an SOP.
If you need access for a quick prod fix, your key gets added to the machine with that explanation and a week (or lees) lifetime.
For Django projects, add the below to manage.py:
env_name = os.environ.get("ENVIRONMENT", "ENVIRONMENT_NOT_SET")
if env_name in TEST_PROTECTED_ENVIRONMENTS and "test" in sys.argv:
raise Exception(f"You cannot run tests with ENVIRONMENT={env_name}")For instance, test code shouldn't have access to production DB passwords. Maybe that means a slightly less convenient login for the dev to get to production, but it's worth it.
One of the reasons I put interactions between databases behind a cli.
There is no code that will protect your db/data. Only replication to a read-only storage will help in such situations.