Hacker News new | ask | show | jobs
by hjkl_hacker 114 days ago
This doesn’t really fix that it can echo the secrets and read the logs. `enveil run — printenv`
2 comments

Not the author but No, the decryption would ask the secret again? The readme mentions it's wiped from memory after use.
Jenkins CI has a clever feature where every password it injects will be redacted if printed to stdout; `enveil run` could do that with the wrapped process?

Of course that's only a defense against accidents. Nothing prevents encoding base64 or piping to disk.