slouchpie
Hi all,
Today I had a problem that I needed to persist API keys from a 3rd party. I wanted to persist them in an encrypted way and I documented what I came up with:
If any grizzled veterans on here have some spare time, please read what I have written and tell me one of:
-
I am about to be pwned and all my base captured if I don’t change something critical
-
I have taken an OK approach but it could be a lot better
-
I am a genius and you will give me a million dollars
Even if nobody reads it, maybe this will help somebody else with a similar problem in the future.
P.S. that website is still being built, so forgive any bad formatting.
Trending in Discussions
Hey there,
It’s been more than a year since we started using LiveView as our main UI library and building a whole library of UI componen...
New
I am happy to introduce the very α version of the new programming language compiled to BEAM.
Welcome Cure.
It has literally three kille...
New
A little off-topic, but I feel like people here have a good head on their shoulders.
I used to be quite good at making software. Was luc...
New
Hi there! :wave:
@frigidcode and I (but mostly him) have been running an Elixir Book club, we’re almost done with Designing Elixir Syste...
New
I’ve been using Emacs as my main code editor for more than a two years. It’s a custom build version although I’ve tried doom emacs and sp...
New
I love Elixir. It’s one of 2 programming languages I’ve ever fallen in love with.
But I don’t use it anymore.
Serverless was the promis...
New
Lately I’ve been thinking about how to organize components as a LiveView application grows. One of the pain points I’ve found (for myself...
New
Other Trending Topics
Edit: 2026 May 15 - This post is archived.
Mob is alive!!
Main docs: mob v0.7.11 — Documentation
A bit of explanation for the slightly c...
New
Hobbes is a low-level distributed database for the Elixir programming language.
Hobbes provides a simple, safe, and scalable storage lay...
New
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New
With AI doing more of the implementation work, I’ve been wondering how much coding I should deliberately keep doing myself.
My main conc...
New
Just published claude-code-elixir, a plugin marketplace for Claude Code with Elixir support. These are the plugins I’ve been using for my...
New
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #library
- #deployment
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #podcasts
- #javascript
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ai
- #ecto-query
- #elixirconf-us
- #blog-post
- #elixir-ls
- #phoenix_html
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #elixirconf-eu
- #api
- #forms
- #metaprogramming
- #hex










Showing Posts 1 to 8- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
Aetherus
If it’s a static key that never changes, you can just put it in a config file which only your service can read. If you feel the file system is not secure enough (for example, some dude steals your whole server), you can use LVM to encrypt the whole hard drive with a passphrase only you know.
slouchpie
That’s a good idea. My actual prod implementation is not revealed. I use the env var in the example for “ease of use”.
Encrypting the hard drive is always good advice!
dch
Nice post thanks!
It’s not clear what your “threat model” is (read https://www.usenix.org/system/files/1401_08-12_mickens.pdf for some helpful humour on this BTW).
My threat model is that due to some unexpected bug in our web stack (OS → reverse proxy →
container → phoenix+BEAM) the code & config files are exposed.
I don’t account for state-level actors (govt spies, etc) who can subvert datacenter controls and gain physical access to the servers, for example. We use separate environments and keys for dev/test vs prod, too.
In this scenario I can expect all of these to be exfiltrated (stolen):
The only thing I’d add to your approach is never to store the the actual key in the code or env vars, if possible.
My general approach for securing keys is as follows:
This doesn’t solve the problem but it does make it harder to subvert.
Personally, I prefer APIs where the authentication is added as an HTTP Header (like
Authorization: Bearer abc123deadcafe123as this can be injected outside the container, on valid outbound requests, by a reverse proxy. This way, the container can be spun up without network access at all, no root privileges, and no useful credentials. This puts a lot of trust in the reverse proxy, but it’s not in the direct path of an attacker, so we win a little bit more here. But in your case you have a (very nice) per-user API key so that doesn’t work.It’s also possible to have a key generated on the fly for each invocation of your program, but that’s advanced vault and may be overkill for your needs.
slouchpie
Thanks for the feedback. I don’t understand everything you have written so I bookmarked to read again over the weekend.
slouchpie
OK I understand this now. What deployment platform are you using? AWS?
dch
Very tin foil, we run our own custom setup outside AWS. I think, in total, over 7+ years, we’ve had less downtime than people using AWS have.
slouchpie
I am very interested in this. Are you able to provide details? I would like to know custom deployments, for similar “tin foil” reasons. Maybe you have a blog post or similar describing your setup?
slouchpie
JFYI I moved domain. New link is here: Symmetric Encryption with ExCrypto in Elixir/Phoenix<!-- --> | Peaceful Programming