Security question: is it safe to have secret keys ...
# prisma-whats-new
l
Security question: is it safe to have secret keys in server-side subscription functions? How I dealt with secret keys before on my VPS was through environment variables, so the keys were never checked into any kind of source control and had to be manually entered into the VPS. I think that was a good practice. Is there anything like that available for the cloud functions that graph.cool supports, or is that unnecessary?
s
This is a good point @lastmjs. You can assume that source code in a Graphcool Function is kept safe. Our execution engine is using the concept of containers to separate functions. For performance reasons all functions within a project are executed in the same container, but there is no way for functions in different projects to interact with each other. Even though it is safe to store secrets in your Graphcool Functions, I think it would be valuable for Graphcool to provide a centrally managed store for environment variables. Could you open a feature request for this? If you decide you need to manage your secrets with environment variables, I would encourage you to look into the Serverless Framework and AWS lambda. It allows you to easily deploy a lambda function with injected environment variables that you can hook into your Graphcool project as a webhook.
👍 1
s
Excellent - Thanks!