puppetlabs-aws icon indicating copy to clipboard operation
puppetlabs-aws copied to clipboard

Need mechanism to relieve need to hardcode AWS api secrets

Open reubenavery opened this issue 7 years ago • 1 comments

I created a related issue in: https://github.com/vcr/vcr/issues/599

(with regard to creating scripted acceptance tests and feature specs)

Relying on developers to diligently scrub their code of secrets prior to commit is a giant security vulnerability. Why can't we rely on either environment variables, or ~/.aws/credentials or ~/.fog?

reubenavery avatar Jul 28 '16 23:07 reubenavery

+1

prozach avatar Jul 28 '16 23:07 prozach