Lesson 1 / 24
What Counts as a Secret
Identify passwords, API keys, tokens and private keys, and tell them apart from ordinary configuration.
Anything that grants access
A secret is a value that gives access to something: a password, an API key, an access token, a database connection string with a password, or a private key. If someone else holding it could act as you, it is a secret.
The life of a secret
A secret is created, stored, used and eventually rotated or revoked. Leaks happen at every stage.
Config or secret?
The port number is ordinary config and is safe to commit. The password and key are secrets and must live somewhere else.
PORT=3000 # config: safe to commit
DB_PASSWORD=... # secret
STRIPE_SECRET_KEY=sk_... # secret
APP_NAME=shop # configHouse keys
Your house address is public information, like config. The key is a secret. You would not tape a spare key to the front door, yet pasting a key into a public repo does the same thing.
Quick check: Which of these is a secret?
- The app's display name
- A cloud API access token
- The HTTP port number
- The log level
Answer
A cloud API access token — A token grants access to a service. Names, ports and log levels do not.