Blog
Notes on secrets, environments, and shipping safely.
Vibecoding Is Leaking Your Secrets Into Chat Logs
AI coding agents read your .env files, print them into context, and save the transcript to disk. Here's how to vibecode without handing every secret to an LLM.
Stop Making New Developers Beg for API Keys
New hire onboarding shouldn't mean a week of Slack DMs asking 'who has the Stripe key?' Fix your env setup in 5 minutes with secrets management.
Your Database Password Is 18 Months Old. That's a Problem.
Static database credentials are a breach waiting to happen. Here's why automatic rotation matters and how to set it up without breaking production.
You Leaked an API Key. Now What?
A step-by-step guide to containing the damage after exposing secrets in git, Slack, or logs—and how to make sure it never happens again.
Stop Hardcoding Secrets in Your CI/CD Pipeline
Why secrets in CI/CD are your biggest blind spot—and how to fix it with service tokens, runtime injection, and automated scanning.
Your .env File Is a Ticking Time Bomb
Why dotenv files are a security risk for teams, and how to stop secrets from ending up in git history, Slack DMs, and shared docs.
KeyEnv vs Doppler: Which Secrets Manager Fits Your Team?
An honest comparison of KeyEnv and Doppler for secrets management. Pricing, features, and which tool works best for different team sizes.
Sync Environment Variables Across Your Team in 5 Minutes
A step-by-step tutorial for sharing secrets securely with your team. Stop pasting API keys in Slack and start using proper secrets sync.
How to Secure Your Secrets in Docker Containers
Learn best practices for managing environment variables and secrets in containerized applications without exposing sensitive data.