Store secrets on my host safely
Some hosts have no environment variables. Here's where keys go instead.
My app uses <stack> on <host> and needs API keys and database passwords. Tell me the right way to store secrets on this host: - Does it support environment variables for my app? If so, where do I set them? - If not, where can I put a config file so it's outside the web root and can never be downloaded by URL? - File permissions for that file. - How my code should read it, with a clear error if it's missing. - How to check nobody can fetch it from a browser. Then: what should I do if a key has already been in a file inside the web root?
Assume a key that was ever downloadable has been downloaded. Rotate it, then fix where it lives.