GuidesProduction setup
Keep the secrets in a file
Put the secret options of ferryd in an environment file that only the user ferry can read.
A secret in the unit file is not safe. The command systemctl show and the list of processes show it.
1 / 3
Each flag of ferryd has an environment variable, except --take-over. Put the secret ones in an environment file, not in the unit file.
Create the file
FERRY_GITHUB_WEBHOOK_SECRET=paste-the-output-of-openssl-rand-hex-32Replace the value with the output of openssl rand -hex 32.
Protect the file
sudo chown ferry:ferry /etc/ferry/ferryd.env && sudo chmod 600 /etc/ferry/ferryd.envThe user ferry owns the file. The file mode 600 lets only the owner read it.