heroku / heroku/roadmap

Secure config vars

Open
#24 23 comments 48 reactions 0 assignees View on GitHub
Security
Dominant language
No language data
Stars
225
Forks
19
PR merge metrics
No merged PRs in 30d

Description

We'd like to provide enhanced security for the most sensitive of config vars for Heroku apps. While config vars are masked today unless you click on them to unmask the ability to unmask **at all** can be undesirable for some levels of secrets.

Workarounds exist of limiting access to the production app, but having config vars that are specifically noted as extra sensitive that become write-only, and cannot be extracted via the Heroku dashboard, seems like a way to make this level of security much more approachable.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.