Database credentials in environment variables?

Viewed 3375

Many developers here on Stackoverflow and on other sites recommend to store the database password in an environment variable. We're using Spring Boot and we'd like to know if it's really a good (safe and common) way to avoid clear text passwords in the application.properties file, even in production? If not, what's the better solution?

Mind that we need different .properties-files for DEV and PROD.

3 Answers

I recommend you to take a look into Spring Cloud Config:

Spring Cloud Config provides server and client-side support for externalized configuration in a distributed system. With the Config Server you have a central place to manage external properties for applications across all environments.

Features:

Spring Cloud Config Server features:

  • HTTP, resource-based API for external configuration (name-value pairs, or equivalent YAML content)
  • Encrypt and decrypt property values (symmetric or asymmetric)
  • Embeddable easily in a Spring Boot application using @EnableConfigServer

Config Client features (for Spring applications):

  • Bind to the Config Server and initialize Spring Environment with remote property sources
  • Encrypt and decrypt property values (symmetric or asymmetric)

You can find a working example of a Config Server here

This is all depending on how you deploy your applications. Spring Boot uses a particular order to how properties are set. See: https://docs.spring.io/spring-boot/docs/current/reference/html/boot-features-external-config.html

There are different ways of not exposing you password to much but it will always be visible to someone with enough access and if they know where to look.

Eg. If you run you application i docker you might want to set all passwords as environment variables.

But another example is to set them as properties when you start your app

$ java -jar myproject.jar --property=value

You have to choose what fits your needs the best.

Related