There are so many secrets spread across dot files. Is it possible to encrypt and store them in remote and de-encrypt when it’s pulled to local machines?
And it adds "how safe are those encrypted secrets [edit: changed from "keys" to more general language] that are committed?" and "what about previous revisions . . . because it's version control?" and "are we sure we're managing offboarding securely?"
There are probably other concerns but those are the ones the immediately shout at me.
https://www.freedesktop.org/wiki/Specifications/secret-stora...
export MY_TOKEN="$(pass token | head -n 1)"Then you can just not track that file in the tool and figure out a safe way to back it up.