A development team is using Git for version control and a CI/CD pipeline. They have a repository containing application code, configuration files, and sensitive API keys. To prevent accidental exposure of these API keys in the repository or during the build process, which security measure should be implemented?
- AEncrypting the entire Git repository with a master password.
- BStoring API keys directly in the `config.yaml` file, but excluding `config.yaml` from `.gitignore`.
- CCommitting API keys to the repository, but only in a private branch.
- DUsing environment variables or a dedicated secrets management service to inject keys at runtime.
Show answer & explanationAnswer & explanation
Correct answer: D. Using environment variables or a dedicated secrets management service to inject keys at runtime.
Sensitive information like API keys should never be committed to source control, even in private repositories or branches, or stored directly in configuration files. The best practice is to manage them externally using environment variables (for less sensitive cases) or, preferably, a dedicated secrets management service (like HashiCorp Vault, AWS Secrets Manager, Kubernetes Secrets) that injects them securely at runtime.
Why the other options are wrong
- A. Encrypting the entire Git repository is cumbersome, difficult to manage for collaboration, and doesn't address the fundamental issue of secrets being in source control.
- B. Excluding `config.yaml` from `.gitignore` means it will be committed, exposing the keys. Even if it were ignored, placing keys directly in such a file is insecure.
- C. Committing keys to *any* branch, even private, carries the risk of accidental exposure (e.g., branch merge, repository leak) and violates the principle of not storing secrets in source control.
Secrets Management Best Practices
Secrets management involves securely storing, retrieving, and auditing sensitive information (e.g., API keys, passwords) to prevent exposure and unauthorized access.
- Never commit secrets to source control.
- Use environment variables for simple cases.
- Prefer dedicated secrets management services.
- Rotate secrets regularly.
Memory trick: Keep keys out of code, inject them securely.