FerryDocs

Keep the secrets in a file

Put the secret options of ferryd in an environment file that only the user ferry can read.

Edit on GitHub
Unit fileshows the secretferryd.envmode 600systemdferryd

A secret in the unit file is not safe. The command systemctl show and the list of processes show it.

1 / 3

Each flag of ferryd has an , except --take-over. Put the secret ones in an , not in the file.

Create the file

/etc/ferry/ferryd.env
FERRY_GITHUB_WEBHOOK_SECRET=paste-the-output-of-openssl-rand-hex-32

Replace the value with the output of openssl rand -hex 32.

Protect the file

Terminal
sudo chown ferry:ferry /etc/ferry/ferryd.env && sudo chmod 600 /etc/ferry/ferryd.env

The user ferry owns the file. The 600 lets only the owner read it.

On this page