Secrets
Credential Isolation
Keep provider credentials specific to each customer deployment and separate from distributable software.
Customer-owned credentials
Server-panel tokens, registrar credentials, payment gateway keys, SMTP credentials and infrastructure API secrets belong to the deployment owner.
Distribution boundary
JKSolutions software distributions are designed to remain free of JKSolutions production provider credentials, test-server passwords and shared environment-specific API secrets.
Operational handling
- Configure secrets after installation.
- Use the minimum provider permissions required.
- Do not publish credentials in screenshots or support posts.
- Rotate credentials when access changes or compromise is suspected.
- Revoke obsolete credentials.