Is there a best practise regarding where to put master.key for a Rails 5.2 app on Digital Ocean?
Background:
- Rails 5.2 allows storing sensitive variables in a file called
credentials.yml.enc credentials.yml.encis encrypted by another file calledmaster.key- You shouldn't put the
master.keyanywhere public or push to Github - But the app needs it to decrypt and access variables in
credentials.yml.enc
On Heroku, it's as easy as creating a environment variable called RAILS_MASTER_KEY in the Heroku UI, but it's not so straightforward for Digital Ocean.
I'm just deploying with git hooks. Nothing special and no CI/CD.
Should I just hardcode the master.key in .bashrc or something? (it feels a little sketchy)