October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk5 min

How to Secure Secrets and Environment Variables in Cloud Coding Sessions

Use platform secret stores, narrowly scope access, and treat any code in a cloud coding session as able to use credentials exposed to its processes. Codespaces, AWS CloudShell, and Google Cloud Shell differ in when secrets appear and what persists.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Store credentials in your cloud development platform’s secret facility, grant each secret only the access it needs, and assume that any code running in a session can read values exposed to its processes. A cloud IDE or shell may also preserve files after shutdown, so check the platform’s actual storage behavior rather than treating a session as disposable.

Use a platform secret store, not repository files

Do not commit API keys or place them in checked-in .env files, Dockerfiles, command output, logs, or screenshots. Use the platform’s dedicated secret settings, then grant access only to the people, repositories, workflows, and cloud permissions that need it. A secret manager reduces the chance of accidental exposure in source control; it does not make a credential safe from code that is allowed to use it.

For GitHub Codespaces, GitHub’s security guidance says: “Always use development environment secrets when you want to use sensitive information (such as access tokens) in a codespace.” Development environment secrets can be managed at personal, repository, or organization level. Organization secrets can be restricted to selected repositories. GitHub documents a limit of 100 secrets per organization and 100 per repository, with a maximum size of 48 KB per secret; check the current limits because product documentation can change.

Know which code can read a secret

An environment variable is not a vault once it is in a running environment. Processes that can access the variable—including scripts, tools, and extensions running in that environment—may be able to use its value. Limit what code you run while credentials are present, and do not expose a production credential to an untrusted repository merely because the work is happening in a hosted VM.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Codespaces: secrets arrive after build and startup

GitHub exports development environment secrets as environment variables into the user’s terminal session after the codespace has been built and is running. They are not available while a Dockerfile or custom entry point is building the environment. A lifecycle script that runs after startup can access them, so the distinction is about phase—not whether a script is trusted. See GitHub’s documentation on account-specific Codespaces secrets.

A newly created or changed secret becomes available when a codespace is created or restarted. Restart an existing codespace after changing a secret; do not expect a running session to acquire the updated value automatically.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Review repository setup and extensions

GitHub notes that a repository’s devcontainer.json can install third-party extensions or run arbitrary postCreateCommand code. Its Codespaces security guidance also describes the VM boundary and recommends opening only trusted repositories and restricting access to features and secrets. Before granting a codespace access, inspect its devcontainer configuration, lifecycle commands, extensions, and repository provenance. A container or VM helps isolate environments, but it does not prevent code running inside an authorized session from using credentials available there.

Cloud-shell credentials and persistence differ by provider

Environment Credential behavior What persists
GitHub Codespaces Development environment secrets are exported to the terminal session after build and startup; they are unavailable during Dockerfile and custom-entrypoint build time. Check files, history, logs, caches, and artifacts; the cited Codespaces guidance does not establish universal cleanup behavior.
AWS CloudShell Console credentials are forwarded to a new session by default. The session receives temporary, regularly rotated IAM credentials scoped to the user’s permissions. Public CloudShell home data is stored in Amazon S3 and persists. VPC CloudShell home data is deleted on timeout, restart, or deletion.
Google Cloud Shell Cloud API calls require authorization prompts; GOOGLE_CLOUD_PROJECT is set from the active console project. The allocated VM user has root privileges. The default VM is ephemeral, but that alone does not prove that every credential or user-created copy has been removed.

AWS CloudShell: use IAM as the boundary

AWS states that CloudShell’s temporary IAM credentials may be scoped to the user’s permissions and that “These credentials are the security boundary, not the container itself.” Use an IAM identity with only the actions and resources needed. Administrators can use IAM policies to block forwarding console credentials into CloudShell; if forwarding is blocked, users must configure credentials manually. See AWS’s CloudShell IAM access guidance and CloudShell security FAQs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Do not infer that files disappear when a CloudShell session ends. AWS distinguishes public CloudShell from VPC CloudShell: public home data persists in S3, while VPC home data is deleted on timeout, restart, or deletion. AWS documents a 20–30 minute inactivity timeout for VPC environments and 10 minutes in AWS GovCloud (US). These are platform-specific behaviors, not a general cloud-shell cleanup guarantee. See What is AWS CloudShell?.

Google Cloud Shell: ephemeral VM does not mean secret-proof

Google describes Cloud Shell as a preconfigured VM that is ephemeral by default, and notes that the VM is not directly associated with or managed by the active project. The allocated VM user has root privileges. Treat all credentials and files available to that VM accordingly; ephemerality is not evidence that copies in shell history, output, or other user-created locations have been removed. See How Cloud Shell works.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Prefer short-lived credentials for automation

For an automated GitHub job that needs AWS secrets, avoid adding another long-lived AWS access key when a federated approach fits. AWS documents using GitHub OIDC for a job to assume an IAM role, then retrieving values from Secrets Manager; its guide uses aws-actions/aws-secretsmanager-get-secrets@v2 and describes mapping retrieved secrets to masked job environment variables. OIDC role assumption provides short-lived credentials rather than requiring a stored static cloud key. Follow AWS’s GitHub Actions integration guidance, and keep the role’s trust policy and permissions narrowly scoped.

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Use a session checklist

  1. Before starting: Put sensitive values in the platform’s secret settings or secret manager. Scope access to the smallest practical set of repositories, users, or cloud actions.
  2. Before opening a repository: Review its devcontainer configuration, lifecycle commands, extensions, and provenance. Do not give secrets to code you would not trust with the same access.
  3. At runtime: Expose each credential only in the phase that needs it. Remember that a process with access to an environment variable may use it; avoid printing values or passing them into logs and artifacts.
  4. Before ending or sharing a session: Check files, shell history, logs, caches, artifacts, and persistent home directories for accidental copies. Confirm whether that environment’s storage persists instead of assuming shutdown wipes it.
  5. If exposure is suspected: Revoke or rotate the credential with its issuer, review relevant access logs, and remove persisted copies.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.