Skip to content

Details

How should we handle credentials and other secrets in Python-applications?
Insights bridging the gap between developer convenience and robust security architecture.
Have you ever accidentally committed a password to Git, or struggled to keep track of API keys across multiple environments? This meeting is for you.

Target audience: Coders, Programmers, Developers

We will enjoy lightning-speed talks from a range of speakers, progressing from the most immediate, day-to-day problems ("I need to put a password in my code") to more sophisticated and strategic solutions.
Opportunity for Q&A at end, and to register interest for future sessions/workshops - greater depth, practical details, etc.

Content:
The problem and the first step
- what is the problem with hard-coded Credentials & Environment Variables?
- the most widely used "first step" solution, .env files
Developer-Focused Tools & Best Practices
- 1password secret resolution for multiple development stages
Structured Storage & Integration
Dedicated, structured secrets-stores and application-specific integrations
- Mozilla SOPS and managing encrypted secrets as code
- Operating System Keychains
- Context-Aware Solutions and choosing the right strategy based on context
Security Infrastructure: Vaults, Abstraction & The Future
- "Federated Cloud Identity")
- Short-lived credentials and workload identities
Wrap-up
- Review
- Q&A and Open Discussion

Speakers:
Oliver Ewart, Supriya Kanchan, Jeremy Stott, John Billings, David Fischer, and Simon Merrick

Related topics

Data Science using Python
Python
Computer Programming
IT Professionals
Database Applications

You may also like