Where to store master.key for Rails 5.2+ app on Digital Ocean

Viewed 283

Is there a best practise regarding where to put master.key for a Rails 5.2 app on Digital Ocean?

Background:

  • Rails 5.2 allows storing sensitive variables in a file called credentials.yml.enc
  • credentials.yml.enc is encrypted by another file called master.key
  • You shouldn't put the master.key anywhere public or push to Github
  • But the app needs it to decrypt and access variables in credentials.yml.enc

On Heroku, it's as easy as creating a environment variable called RAILS_MASTER_KEY in the Heroku UI, but it's not so straightforward for Digital Ocean.

I'm just deploying with git hooks. Nothing special and no CI/CD.

Should I just hardcode the master.key in .bashrc or something? (it feels a little sketchy)

0 Answers
Related