Azure / apiops

APIOps applies the concepts of GitOps and DevOps to API deployment. By using practices from these two methodologies, APIOps can enable everyone involved in the lifecycle of API design, development, and deployment with self-service and automated tools to ensure the quality of the specifications and APIs that they’re building.
https://azure.github.io/apiops
MIT License
275 stars 162 forks source link

[Question] I noticed in the example publisher configuration file, the Subscription GUID is suppose to be filled in. #534

Closed zcarroll4 closed 2 months ago

zcarroll4 commented 2 months ago

Release version

Most recent version

Question Details

Is storing the Subscription ID in source code a security concern?

image

Expected behavior

N/A

Actual behavior

N/A

Reproduction Steps

N/A

See configuration.prod.yaml for example.

"subscription Guid goes here" in several places throughout the file.

github-actions[bot] commented 2 months ago
  Thank you for opening this issue! Please be patient while we will look into it and get back to you as this is an open source project. In the meantime make sure you take a look at the [closed issues](https://github.com/Azure/apiops/issues?q=is%3Aissue+is%3Aclosed) in case your question has already been answered. Don't forget to provide any additional information if needed (e.g. scrubbed logs, detailed feature requests,etc.).
  Whenever it's feasible, please don't hesitate to send a Pull Request (PR) our way. We'd greatly appreciate it, and we'll gladly assess and incorporate your changes.
waelkdouh commented 2 months ago

Feel free to store it as a secret. Just follow the steps demonstrated for the secret entry in the file which uses replace token extension.