Protect API keys, manage SSH credentials, enforce `.gitignore` rules, prevent secret leaks to public Git repos using pre-commit hooks, and handle credential rotation.
Accidentally committing an AWS secret key or Stripe API token to a public GitHub repository can result in tens of thousands of dollars in unauthorized bot charges within minutes. Developer security hygiene is a core career requirement.
Master secret prevention tools: `.gitignore` discipline, `gitleaks` pre-commit hooks, SSH Ed25519 key pair generation, environment variable separation (`.env`), hardware 2FA (YubiKey), and secret revocation protocols.
Install and configure `gitleaks` pre-commit hooks to block secret keys before code is committed.
Generate secure SSH keys (`ssh-keygen -t ed25519`) and configure `~/.ssh/config` for multiple Git accounts.
Separate environment variables safely using `.env.example` templates and encrypted secret managers.
Execute emergency secret revocation and Git commit history purging (git-filter-repo / BFG Repo-Cleaner) if a leak occurs.
Prevents automated crypto-mining bots from exploiting leaked cloud keys.
Guarantees customer data and company secrets remain confidential.
A major security breach caused by hardcoded credentials can derail developer careers.
A junior developer accidentally pasted `OPENAI_API_KEY=sk-proj-12345` inside `next.config.js`. During `git commit`, the Gitleaks pre-commit hook flagged the secret and aborted the commit instantly.
Impact: Saved an estimated $10,000+ in potential API abuse charges.
✗ Bad Approach
Just running `git rm` in a new commit and pushing.
Why it failed: The secret remains in the Git commit history, easily extracted by automated scraper bots.
✓ Better Approach
1) Revoke/rotate the AWS key immediately in AWS IAM, 2) Purge the secret from Git history using `git-filter-repo` or BFG Repo-Cleaner, and 3) Force push.
Why it works: Inactivates the credential immediately and removes it from repository history.
Key Takeaway: Credential revocation must happen first because Git history scrapers index commits in real-time.
❯ SSH & Key Pair Management
ssh-keygen -t ed25519 -C "your_email@example.com"Generate modern, secure Ed25519 SSH key pair.
$ ssh-keygen -t ed25519 -C "user@gmail.com"eval "$(ssh-agent -s)" && ssh-add ~/.ssh/id_ed25519Start background SSH agent and register private key passphrase.
$ ssh-add ~/.ssh/id_ed25519ssh -T git@github.comTest SSH connection authentication with GitHub servers.
$ ssh -T git@github.comcat ~/.ssh/id_ed25519.pubDisplay public SSH key for copying to GitHub/GitLab account settings.
$ cat ~/.ssh/id_ed25519.pub❯ Secret Scanning & Gitleaks
gitleaks detect --source . --verboseScan entire local git repo for leaked secrets and API keys.
$ gitleaks detect --source .gitleaks protect --staged --verboseScan staged git changes prior to committing code.
$ gitleaks protect --stagedbrew install gitleaksInstall gitleaks CLI tool via Homebrew on macOS/Linux.
$ brew install gitleaks❯ Emergency Git History Secret Purging
git-filter-repo --invert-paths --path .envPurge sensitive file entirely from all past git commit history.
$ git-filter-repo --invert-paths --path .envbfg --delete-files .envAlternative BFG Repo-Cleaner command to scrub leaked files from git history.
$ bfg --delete-files .envgit push origin --force --allForce push cleaned commit history to remote repository after secret purge.
$ git push origin --force --allAutomated git hooks (`.pre-commit-config.yaml` or Husky) that scan staged git diffs for regex patterns matching AWS keys, Stripe tokens, and RSA private keys.
Rejects the git commit before code ever leaves your laptop.
Using modern, high-security Ed25519 elliptic curve keys (`ssh-keygen -t ed25519 -C "email"`) rather than legacy 2048-bit RSA keys.
Provides superior cryptographic security with shorter key lengths.
Committing `.env.example` containing empty variable names while adding real `.env` files containing live credentials to `.gitignore`.
Documents required secrets safely for teammates without exposing values.
Prevents posting API keys publicly in course assignment GitHub repos.
Protects personal credit cards tied to OpenAI or AWS accounts during rapid hackathon builds.
Prevents catastrophic leaks of enterprise customer database credentials on day one.
Crucial for passing SOC2 security audits and protecting production customer data.
Ensures external contributors cannot extract maintainer tokens from CI/CD pipeline logs.
Follow this exact sequence if a secret key is accidentally pushed to Git:
Block secrets at the command line before committing.
Set up automated local secret scanning across all your git repositories.
Secure server and GitHub access.
Generate and manage modern Ed25519 SSH keys securely.
Hardcoding API keys or secrets inside client-side frontend React components
Keep API keys in server-side API routes (`app/api/*`) or Server Actions without `NEXT_PUBLIC_` prefixes.
Any key embedded in frontend JS bundles is visible to any browser user via DevTools.
Set up a global gitignore file (`git config --global core.excludesfile ~/.gitignore_global`) that automatically ignores `.env`, `.env.local`, `.pem`, and `*.key` files across every repository on your computer.
Tip: Prevents accidental commits even if a project-level `.gitignore` is missing.
Global ~/.gitignore_global Safety Template
# Global Git Ignore Rules .env .env.* !.env.example *.pem *.key *.pfx *.p12 id_rsa id_ed25519 secrets.json credentials.json .DS_Store
Save to `~/.gitignore_global` and set `git config --global core.excludesfile ~/.gitignore_global`.
Environment variables allow the same codebase to run in development, staging, and production environments with different credentials without hardcoding secrets in source files.
Prevent secret leaks using automated pre-commit scanning hooks like Gitleaks.
Never hardcode API keys or credentials in source code files.
If a leak occurs, revoke the credential first before attempting Git history rewrites.
THREAT SURFACE: HARDENED
“Every developer is a target. Defend your identity and your code.”