CI secrets, webhook secrets, mirror tokens and APNs device tokens are stored in clear in SQLite: build_secrets.value, webhooks.secret, mirrors.token, push_devices.token. The code base has no at-rest encryption; protection is file permissions (database 0640, data directory 0750) and the write-only interface. Anyone who reads the database file or a backup gets every one of them.
- Encrypt these columns with a key held outside the database (a file under
/etc/gitbay, mode 0600, not in backups), or document the decision not to. - Rotation path for the key.
See Architecture/06-Data-and-Cryptography and 09-Controls.
referenced in commit fc5b1b67a2 by cmc: wiki: Architecture overview names diagrams; titles drop their numbers; gaps filed
2026-09-28 04:36 UTC