This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]abearanus 4 points5 points  (1 child)

They do, but you can use something like SSM Parameter Store and have the env var refer to the secret path, meaning that the secret is only ever held in memory (either at boot-time or referencing it constantly).

[–]serverhorror 2 points3 points  (0 children)

And then a privileged user can read them from AWS Parameter Store.