The .env file contains all the credentials used across your application. It can prove fatal if received by any unauthorised entity. So, don’t share the credentials, or share them safely.
Why .env and why should it be kept secure?
- To avoid unauthorised access to your services
- Keeping your code and credentials separate
- To easily change the configuration and credentials
Best practices for the purpose:
- Do not share; just use different credentials for different individuals
- Share through a secure platform
- Share by encrypting the credentials
Developers frequently paste .env snippets into Slack, Microsoft Teams, or email threads. Once pasted:
- It remains permanently stored in chat logs
- It gets indexed by third-parties.
- It is exposed if any chat bot or integration is compromised.
You should choose a secure platform if you want to store or share credentials. We'll see how to use Ilusion Secure Vault for this purpose and why it provides overall security.
What does the Ilusion Vault provide for the storing and sharing of env files?
You can choose whether to share the file or store it. For just sharing, you just need to create a shareable link without needing to be authenticated.
One-Off Secure Sharing (No Account Required)
Ilusion Vault has a page that lets you securely share any file or text as a guest user. So, after the expiry of the link, no record will remain. You can either add the content of the file as a text payload or upload the file itself.
There are various configurations you can use when creating the link:
- Expiry duration: The access link will be deactivated after the set duration.
- Burn-On-Read: Access will be revoked if the content is read once.
- Decryption Passphrase: The key that will be used to encrypt/decrypt the content.
- Custom Link Slug: Custom readable link for access
Steps to generate a secret:
- Add an
.envfile on the tools/encrypted-share page - Choose an expiry period & enable burn-on-read
- Enter the decryption passphrase and generate link
- Use the link to view the
.env
The link will be generated for accessing the content and will require the decryption key. The link will be deactivated after the chosen time during creation.
Encrypted Vault Storage (Persistent Workspace)
As the name suggests, the platform is a secure vault of files with zero-knowledge architecture. The .env file is stored in the vault with encryption. The encryption takes place in the browser itself, so only the encrypted content is saved to the server.
You have a stored file that can be shared easily by generating a link in the vault itself.
You should use Vault if you are frequently going to share the file; otherwise, the one-off option is much better.
Conclusion:
The .env file contains the configuration and keys that should be kept secure. You should use secure platforms like Ilusion Vault to share them. It has a zero-knowledge architecture with easier access.


Top comments (0)