Skip to content

Secret Management

Rules

  • Store secrets in environment variables or a secured secret manager.
  • Use .env.example for placeholders only.
  • Never commit .env, private keys, certificates, or production credentials.
  • Never log Authorization headers, tokens, passwords, private keys, or unredacted MongoDB URIs.
  • Config dumps must redact secrets.

text /etc/iqv-integration-api/.env /opt/iqv-integration-api/bin/iqv-integration-api

The environment file should be readable only by the service account.