A live key in a public build log is found by scrapers in minutes. Here is what we saw, and what the fix looked like.
In August we planted three test keys in public CI logs, each scoped to a sandbox with no money in it, and watched. The first automated login attempt arrived 11 minutes after the log went public. By the end of the first hour, all three keys had been tried.
Why build logs
Most teams keep secrets out of their code. Fewer think about what their build prints. A debug line, a failing test that dumps its environment or a verbose deploy script is enough.
What the fix is
Rotating the key stops the damage, but it does not stop the next leak. The fix Quorum opens moves the value into your secrets manager, replaces the line with a reference and adds a check that fails the build if a live key pattern appears in output again.
The pull request is small on purpose: one line in the env file, one resource in Terraform, one step in CI. Two people can review it in the time it takes to read this post.
More from the blog
8 min read
We only open a pull request when we can show the path
A vulnerable package you never call is not an emergency. Here is how we decide what deserves a pull request.
Marcus Hale
5 min read
Two approvals, not zero: why Quorum will never auto-merge
We get asked for auto-merge every week. Here is why the setting does not exist.
Elena Voss
7 min read
Scanning 1,284 resources an hour in four minutes
How the scanner stays fast enough to run every hour without making your cloud bill notice.
Owen Park
Run a free scan on one repo
Connect one repo and one cloud account with read-only access. You get the findings and the first fix pull requests within a day, and you keep them either way.
