On Mon, May 19, 2014 at 3:22 PM, Benjamin Iandavid Rodriguez
<
ian...@gmail.com> wrote:
> I made that recommendation as he stated that the answer from github was to
> set the secret keybase using export. So please dont be rude and have a
> little more respect for those who aren't as experienced as you are.
My apologies, I meant neither rudeness nor disrespect.
The whole idea of loading initialization values through environment
variables in the name of "security" seems pointless to me if you're
going to put them all in a shell init file anyway :-)
We already put our DB server passwords in a file that's not typically
included in the app's repository but symlinked on deploy, and I've
never seen anyone express any issues with that.
In any case, the .bashrc approach *will* be a problem if the app's
started at boot time as a different user...
FWIW,