awslabs / awslabs/amazon-app-runner-deploy

Github secrets become public env variables in AWS console

Open
#45 4 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
60
Forks
34
PR merge metrics
No merged PRs in 30d

Description

Github secret values are exposed as environment variables in AWS App Runner console, everyone can access them. Am I missing something?

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the deployment and inspecting how GitHub secrets are passed into AWS App Runner, then check the resulting environment variables in the AWS App Runner console. Done means secret values are no longer publicly visible there while the deployment still receives the required configuration.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, github-actions, typescript
Domain
ci-cd, cloud, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.