Chapter 5: Bash Scripting for Automation
5.7 Secrets — never hardcode
# BAD — do not do this
PASSWORD="real-password-here"
# BETTER for labs — read from environment; set outside the file
DB_PASSWORD="${DB_PASSWORD:?set DB_PASSWORD in the environment}"
| Store here | Never store here |
|---|---|
| Environment variables / OS secret store | Script committed to Git |
| CI secret settings (later chapters) | Screenshots in the repo |
Local .env (gitignored) |
Public README |
Pass tokens into the process from outside. Chapter 2 already blocked .env via .gitignore — keep scripts aligned with that rule.
No real cloud keys
Do not paste AWS access keys into scripts or Git. Use roles and temporary credentials patterns from the AWS course when cloud access is required.