31 karma · joined February 27, 2009
Professionally I’ve been building web based solutions since 2000, using Ruby since 2006 with Ruby on Rails following in 2008. I love working on general architecture and backend topics and used a wide range of tools and technologies there.
[ my public key: https://keybase.io/mreinsch; my proof: https://keybase.io/mreinsch/sigs/A9OLELaI2cpWzrv_qpouqEdjxm0KWYGtHcuJkpG70bs ]
I applaud to postfix for sanitising the ENV, and it's very good practice to do so. But are all the frameworks doing it correctly? Maybe some code is then also just spawning new processes without sanitising? You could argue that's a bug then (which I completely agree), but not all projects are run like postfix...
ENV variables are not restricted by user though, your process can spawn another process under a different user and give it the same environment. It's the nature of the environment that it is usually inherited from the parent which causes the issues when we're talking about secrets.
Alternatively, if you're running on AWS you could also fetch the secrets config file from an S3 bucket which is only accessible by your production servers.
But there is one main difference: that tool would need to do so explicitly, with the intent of reading (and possibly exposing) your secrets. For me, that's a huge difference from having the secrets being implicitly available to the process through the processes environment.