Archival.dev now encrypts secrets
Secrets on archival.dev are now encrypted at rest automatically
Archival recently introduced a 'secrets' type - the archival rust lib and CLI just treats these a little differently than other strings, in that it refuses to render them but otherwise they're the same as strings.
The reason for this introduction was to allow (via carriers) the use of privileged operations without exposing secrets on the client - for instance, I use this at my bar to read and write to a google sheet via a service account, which allows guests to book directly into our host sheet.
However it bothered me that the use of these secrets meant that you really needed to make sure your site repo was never public. I'd much prefer to share my site repos with the world, but as soon as a secret was introduced, I'd need to close the source since there would be plaintext secrets in git.
As of today, that tradeoff is no longer necessary. Archival automatically encrypts all secrets before writing to backing git repos, and decrypts values when editing - so you can interact with secrets just like before, but public repos will only have encrypted values for secrets, which can't be read without the editor.
This is another example of how separating content from presentation can be very powerful. Having strong types for these values means that we could make this change without introducing a new API or requiring configuration.
After I clean out my repo history or rotate my service account keys, I'll be able to make my restaurant site's repo public, so other folks can take a look at how to build a robust reservation system entirely on Archival and google sheets.
Comments
Add your thoughts
Loading comments…