Lesson 1 / 24

What Counts as a Secret

Identify passwords, API keys, tokens and private keys, and tell them apart from ordinary configuration.

Anything that grants access

A secret is a value that gives access to something: a password, an API key, an access token, a database connection string with a password, or a private key. If someone else holding it could act as you, it is a secret.

The life of a secret

A secret is created, stored, used and eventually rotated or revoked. Leaks happen at every stage.

Four stages: create, store, use, rotate.
Figure 1.1 — Create, store, use, rotate.

Config or secret?

The port number is ordinary config and is safe to commit. The password and key are secrets and must live somewhere else.

PORT=3000                 # config: safe to commit
DB_PASSWORD=...           # secret
STRIPE_SECRET_KEY=sk_...  # secret
APP_NAME=shop             # config

House keys

Your house address is public information, like config. The key is a secret. You would not tape a spare key to the front door, yet pasting a key into a public repo does the same thing.

Quick check: Which of these is a secret?

  • The app's display name
  • A cloud API access token
  • The HTTP port number
  • The log level
Answer

A cloud API access token — A token grants access to a service. Names, ports and log levels do not.