[NX-204] Create production secret management guide #14
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Goal
Avoid insecure secret handling in production deployments.
Scope
Acceptance Criteria
NX-204 Completed
Implemented production-focused secret handling guidance and removed ambiguous practices.
What was delivered
docs/security/secret-management.md.envtemplates:.env.exampleops/.env.exampleScope Coverage
JWT_SECRET_KEYENCRYPTION_KEYDB_PASSWORDAcceptance Criteria Mapping
Clear “do/don’t” section exists
Met: documented in
docs/security/secret-management.md.No recommendation to hardcode secrets
Met: hardcoding is explicitly marked as forbidden across docs/templates.
This closes NX-204.