Skip to content

Default behaviour should be to not automatically set any Lambda environment variables  #89

Description

@neverendingqs

Right now, all Lambda function environments are configured with all variables in the dotenv file(s). This can easily cause security issues by setting environment variables that contain secrets (e.g. SENTRY_SECRET gets set when none of the Lambda functions use it). As well, it can cause confusion on what is happening on different environments (e.g. #65).

The new default value should be functionally equivalent to:

custom:
  dotenv:
    include: []
  • Update README to recommend new safe default
  • Update README to warn about deprecation
  • Add or update toggle to switch behaviour on major version bump

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions