This article has about as much insight as I would expect from a "nodejs-security.com" article. This article spends a good deal of time conflating two things: putting stuff in .env and using environment variables. The application-parsed .env file is one of the most poorly thought-through ideas that has taken hold in modern application development. It takes something you can do in literally a couple lines of shell (as…
Also annoyed that the title has > and here's how to do it better And then basically just says go use a vendor solution. Cool.
I know vendors secret stores are better.
But what do I do that isn’t vendor-locked and is remotely as simple as environment variables?