Inside ZCode: Silently uploading your Git history to the cloud
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Inside ZCode: Silently uploading your Git history to the cloud
Unofficial Hacker News client; not affiliated with Y Combinator.
philbo · · focus · HN ↗
I'm sure there's a perfectly reasonable explanation for it, which has nothing at all to do with exfiltration of secrets, but it does amuse me when it happens. I imagine the labs have access to lots of secrets that various actors would like to get their hands on...
(shameless plug for my own harness, which is open source and doesn't have a backend to send any data to: <a href="https://www.opairdev.org/" rel="nofollow">https://www.opairdev.org/ )
thehamkercat · · focus · HN ↗
Encrypt: sops encrypt --input-type dotenv --output-type dotenv .env > secrets.enc.env
then rm .env
You can then run your script/dev with: sops exec-env secrets.enc.env 'docker xxxx' (it will ask you for your password, or touch-id to decrypt the secrets)
I like this because this way the .env doesn't sit in the directory at all, and is only passed to your dev environment and stays in it while it's running
Decrypt back to a file (if you ever want that): sops decrypt secrets.enc.env > .env
---
Well ofc, any agent can do docker inspect to get all those env vars, but atleast reading the dotfiles won't do anything
you can also edit the file with: sops --input-type dotenv --output-type dotenv secrets.enc.env
booi · · focus · HN ↗