awslabs / awslabs/amazon-app-runner-deploy
Github secrets become public env variables in AWS console
Open
- Dominant language
- TypeScript
- Stars
- 60
- Forks
- 34
- PR merge metrics
- No merged PRs in 30d
Description
Github secret values are exposed as environment variables in AWS App Runner console, everyone can access them. Am I missing something?
Contributor guide
Research direction
Start by reproducing the deployment and inspecting how GitHub secrets are passed into AWS App Runner, then check the resulting environment variables in the AWS App Runner console. Done means secret values are no longer publicly visible there while the deployment still receives the required configuration.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, github-actions, typescript
- Domain
- ci-cd, cloud, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100