Skip to content

ReferenceThe 22 checks

Secrets in files

Security checksecrets-in-files

What it reads

Environment files, Compose files and shell history in the folders listed under secrets.paths in /etc/kiyesi/config.yaml. Kiyesi reports where a secret is, never its value.

Does it need root?

It needs root for part of what it reads. Other users' files and /root can be read only by root. Without root, that part is skipped and never counted as passed. Run sudo kiyesi scan to include it.

When it passes

The report lists it as passed, in these words:

  • No exposed secrets in count files checked

What it can find

Warning

path holds secrets and every user on this server can read it

Any user or program on the server can read the secrets in this file.

Fix
sudo chmod 600 path
Warning

A secret is written into path at line line

Anyone who can read this file, or the repository it is in, has the secret. Keep secrets in an env file only the owner can read.

Fix
Move the value to an env file with chmod 600, and point env_file at it in path
Warning

A secret was typed into shell history in path at line line

Shell history is kept in plain text, so the secret stays on disk after the command ran.

Fix
Delete line line from path, then change the secret