GuidesProduction setup
Tokens and secrets
Give each tool its own API token, and replace a token or a secret immediately when it leaks.
Each tool has its own token. Each token gives full access.
1 / 3
The checklist
- Give CI its own token. Create a named API token with an expiry for each pipeline or script. Do not share the server token. Then you can revoke one token and leave the others.
- Use secrets for hooks. Set a random
--github-webhook-secret. - Revoke a leaked token. Use the table below.
If a secret leaks
| Secret | What to do |
|---|---|
| An API token | Revoke it under Server → Account in the dashboard. It stops immediately. |
| The server token | Stop ferryd, delete <data-dir>/api_token and start ferryd again. It makes a new token. |
A token from --api-token or FERRY_API_TOKEN | Change the value. |
| The password | Change it under Server → Account. Ferry signs out each other browser. |
| A deploy hook | Rotate it with ferry deploy-hook rotate NAME. |