Where do you store you credentials like secret key , mail passwords, db passwords?
I made a post on https://security.stackexchange.com/questions/19785/security-conce
application.conf
supports environment variables, e.g. db.default.user=${DB_USER}
. You can pass it as a console parameter (which is not safe since it appears in ps
), or more safely set it as an environment variable.
On Heroku, set the environment variable via heroku config
, e.g. heroku config:add DB_USER=MyDBAdmin
.
Locally you can set them via export DB_USER=MyDBAdmin
, or add them to your ~/.bash_profile
(if you use bash).