a month ago
I recently saw the discussion around the Zeabur security incident and it made me take another look at my own deployment setup.
For people running production apps on Railway, what security practices do you consider essential?
I’m especially interested in secrets/API keys, credential rotation, and what you do if you think a credential might have been exposed.
Would be interested to hear how others handle this in real-world projects.
Pinned Solution
a month ago
"What security practices do you consider essential?"
All of the common ones (not committing .env files, rotating credentials immediately after a suspected leak, etc.
"What do you do if you think a credential might have been exposed"
Rotate it.
1 Replies
a month ago
This thread has been opened as a bounty so the community can help solve it.
Status changed to Open Railway • about 1 month ago
a month ago
"What security practices do you consider essential?"
All of the common ones (not committing .env files, rotating credentials immediately after a suspected leak, etc.
"What do you do if you think a credential might have been exposed"
Rotate it.
Status changed to Solved changeshop • about 1 month ago