Secret Management¶
Rules¶
- Store secrets in environment variables or a secured secret manager.
- Use
.env.examplefor placeholders only. - Never commit
.env, private keys, certificates, or production credentials. - Never log Authorization headers, tokens, passwords, private keys, or unredacted MongoDB URIs.
- Config dumps must redact secrets.
Recommended Ubuntu layout¶
text
/etc/iqv-integration-api/.env
/opt/iqv-integration-api/bin/iqv-integration-api
The environment file should be readable only by the service account.