Many developers here on Stackoverflow and on other sites recommend to store the database password in an environment variable. We're using Spring Boot and we'd like to know if it's really a good (safe and common) way to avoid clear text passwords in the application.properties file, even in production? If not, what's the better solution?
Mind that we need different .properties-files for DEV and PROD.