Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

The tutorials all suggest storing your tokens as plaintext #14

Closed
joerunde opened this issue Jan 23, 2025 · 2 comments · Fixed by #22
Closed

The tutorials all suggest storing your tokens as plaintext #14

joerunde opened this issue Jan 23, 2025 · 2 comments · Fixed by #22
Assignees

Comments

@joerunde
Copy link
Contributor

Just a heads up that all of your tutorials suggest setting your HF token in plaintext as an environment variable in the deployments like

    env:
      - name: HF_TOKEN
        value: <YOUR_HF_TOKEN>

This might be fine to do on a local minikube cluster on your machine, but it's super unsafe to do on a remote cluster.

I'd suggest setting up a secret in the helm chart to hold the token, so that it can be safely referenced in the deployment instead like:

    env
       - name: HF_TOKEN
         valueFrom:
           secretKeyRef:
             name: hf-token-secret
             key: token
@ApostaC ApostaC self-assigned this Jan 24, 2025
@ApostaC
Copy link
Collaborator

ApostaC commented Jan 24, 2025

Thanks for pointing it out! This is on our current TODO list and will be updated soon.

@ApostaC
Copy link
Collaborator

ApostaC commented Jan 26, 2025

Hey @joerunde , I just created PR #22 to fix this. Feel free to take a look and leave your comments there.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants