Securing application configuration, while still getting shit done
blog.rainforestqa.com
blog.rainforestqa.com
There's a fairly complete example there, plus discussion. (It's worth mentioning that many of the git maintainers find this to be an odd use of the git filters feature, because it doesn't let you diff things. But of course, that's not the point.)
A later example tries to fix this by using deterministic encryption with openssl instead of gpg, but it's insecure because it accomplishes the determinism by using either ECB mode or CBC mode with a fixed IV.
The proper solution is to use a real deterministic encryption scheme (such as CTR mode with the nonce derived from a HMAC of the plaintext), and also use a diff filter so git diffs work. Not only does git work properly, it's actually secure too! My project, git-crypt[1], works this way.
[1] newer versions of git do some caching here, so the clean filter might not always be invoked, but it's still invoked often enough to cause problems
https://www.agwa.name/projects/git-crypt/
Be careful with some of the other git encryption projects out there - most of them get the cryptography wrong, by using either ECB mode or CBC mode with a fixed IV.
In the meantime, you can accomplish this by storing the git-crypt key in the repository, but encrypted using GPG with multiple recipients (much like your approach). Then you wrap `git-crypt init` in a script that first decrypts the key using GPG before feeding it to `git-crypt init`. To add a new developer, you just re-encrypt the git-crypt key with an additional recipient.
> We add the sensitive environments to .gitignore; for us this is production.txt, qa.txt and staging.txt. These are never committed.
> We get a history of changes in git (though it’s way more of a pain to use as you have to decrypt different versions)
So you have a history of changes, but only for the dev environment? Seems like that wouldn't be terribly useful, but maybe I'm missing something.
For my personal projects, it enables me to host my projects on public github repos, including configuration files, which was traditionally a pain point.
Solved.
edit: looks like the #comment anchor doesn't expand the comment section automatically. Search for the comment by "ntnt"