Skip to content

Environment Variables #3

Description

@safesploit

Store sensitive environment variables (like database passwords) securely in a .env file and use them in docker-compose.yml.

This will make it easier to manage sensitive information without exposing it directly in the configuration.

Activity

  1. safesploit commented on Jan 28, 2024

    @safesploit
    OwnerAuthor

    Create a .env File

    Create a .env file in the same directory as docker-compose.yml.

    APACHE_PORT=8080
    MYSQL_ROOT_PASSWORD=mysecretpassword
    
  2. safesploit commented on Jan 28, 2024

    @safesploit
    OwnerAuthor

    Hard-coded values

    • build.sh
    • config/doogle-user.sql

    Modify docker-compose.yml

    At present docker-compose.yml already uses environment variables. So we can ignore the need to replace hard-coded values in the docker-compose.yml.

    Modify build.sh

    build.sh has hard-coded values

    This can be resolved as such:

    hard-coded

    link

    $dbpass = "PASSWORD_HERE";
    

    environment variable

    \$dbpass = '${MYSQL_ROOT_PASSWORD}';
    
  3. safesploit commented on Jan 28, 2024

    @safesploit
    OwnerAuthor

    .gitignore

    # macOS system files
    .DS_Store
    
    # Ignore directories containing generated files (add more as needed)
    /vendor/
    /node_modules/
    
  4. safesploit commented on Feb 1, 2024

    @safesploit
    OwnerAuthor

    Use a Secrets Manager

    HashiCorp Vault

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions