Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / NewStats: 3,201,398 members, 7,978,265 topics. Date: Friday, 18 October 2024 at 01:08 AM |
Nairaland Forum / Science/Technology / Programming / Help On Deployment On Heroku (1177 Views)
What Other Alternative To Heroku / Why Is Heroku Not Setting My Cookie / Help With Node.js App Deployment To Heroku (Solved!!!) (2) (3) (4)
Help On Deployment On Heroku by gbolly1151(m): 3:08pm On Nov 26, 2019 |
When deploying django to heroku why should (Case1) SECRET_KEY = os.environ.get("SECRET_KEY", "YBWHGRHH" INSTEAD OF (Case2) SECRET_KEY=os.environ['SECRET_KEY'] In my own view the secret key is been exposed in case 1 but more secured in case2 |
Re: Help On Deployment On Heroku by Ajibel(m): 9:27pm On Nov 26, 2019 |
In case 1 it means the default value you set would be used as secret key if you didn't set a SECRET KEY in heroku's env. In case 2 because there's no default, an error will be thrown if you fail to set the key in the env 2 Likes |
Re: Help On Deployment On Heroku by gbolly1151(m): 8:46am On Nov 27, 2019 |
Ajibel: Which one is the best? |
Re: Help On Deployment On Heroku by Ajibel(m): 9:25am On Nov 27, 2019 |
gbolly1151: It depends on your choice. I don't know the best, but I have used several patterns. Here is an idea of what I do with Flask: if os.environ.get('SECRET_KEY'): ........SECRET_KEY = os.environ.get('SECRET_KEY') else: ........SECRET_KEY = 'SECRET_KEY_ENV_VAR_NOT_SET' ........print('SECRET KEY ENV VAR NOT SET! SHOULD NOT SEE IN PRODUCTION') But again I think to have a .env file where you set your private keys and read from it is what I have seen many open source projects do. Since you're using heroku, go through their django setup walkthrough. I believe whatever pattern they make use of there is what you should go with. 1 Like |
Re: Help On Deployment On Heroku by gbolly1151(m): 12:10pm On Nov 29, 2019 |
Ajibel: Thanks it is really helpful I understand that dyno is a virtual file system on which django app are served and can go off anytime, when this happen, do i need to set the config var again to start my app when dyno is on again? |
Re: Help On Deployment On Heroku by Ajibel(m): 1:33pm On Nov 29, 2019 |
gbolly1151: I haven't had any experience using heroku in this case but what I know is that since the config var you set from the start are persistent, then you wont need to set a new config var again whenever your app is restarted. 1 Like |
Re: Help On Deployment On Heroku by gbolly1151(m): 4:31pm On Nov 29, 2019 |
Ajibel: Yea thanks...got it now....after reading their doc, i knew that the config var are kept just like the source code. Whenever dyno loads, config var are set in the environment. So no need of setting the config var again |
Re: Help On Deployment On Heroku by HassieMalcomson(f): 2:23pm On Oct 10, 2023 |
The Heroku key can only be accessed if you have exposed it to the client side. However, if your case is different, then you should approach the setting option and proceed with the config. Here, you should enable this: heroku config: set SECRET_KEY="...". Yes, the Heroku environment is considered highly secure if you keep the key secret. On the other hand, it is also important that you follow the right method to deploy your application on Heroku. If you are using GitHub, then you can simply go with this source https://blog.back4app.com/deploy-to-heroku/ and it will answer all of your queries about deployment. Also, don't forget to utilize protected places to store keys like Heroku Config Vars and Heroku add-ons. You should also rotate the keys to avoid unauthorized access. Hopefully, it will also help you. |
(1) (Reply)
Programmers:Your Thread Of Polls (Come and Vote Oh) / See My Single Page Web App With React Js / How To Create A Screensaver With Visual Basic
(Go Up)
Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health religion celebs tv-movies music-radio literature webmasters programming techmarket Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10) Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 19 |