shell=False Is a Small Setting with a Large Security Boundary
Passing an argument array directly to exec avoids an entire class of shell expansion and injection behavior.
TOPIC
Lessons, explainers, experiments, and implementation notes.
Passing an argument array directly to exec avoids an entire class of shell expansion and injection behavior.
Keeping host execution outside the portal containers limits what a web compromise can directly control.
The strictest-looking file mode is not automatically the safest usable mode when a non-root service must read the key.
Version-aware hardening matters because a security control can disappear or change semantics between releases.
Dropping container privileges is only safe when mounts, ownership and startup scripts are designed for the new identity.
Production readiness has to treat leaked credentials as compromised even after the file disappears from the latest commit.
If the application cannot pin sensitive memory, the container and host memory policy becomes part of the threat model.
Publishing a certificate means every directory in its path must support the intended reader, even if neighboring secrets remain private.
A file can have the right contents and still be unusable when directory traversal or group permissions are wrong.
A service can be allowed through one protected directory without being allowed to inspect the directory itself.