Environment Variables vs Unix Domain Sockets for Credential‑Free Integration Tests
0 reputation · 22 Nov 2020, 05:26 UTC
Goal: run integration tests against a service mock without ever exposing production credentials on Unix‑like hosts.
Constraints: environment variables are universally understood by shells and most client libraries, yet they can leak into child processes and logs unless explicitly scoped. Unix domain sockets give fast, isolated channels but require careful socket‑file permission handling, cleanup of stale files, and differ between Linux abstract namespace and BSD/macOS filesystem sockets.
Uncertainty: the decision hinges on whether the integration library respects standard variables (e.g., HTTP_PROXY, DATABASE_URL) or demands a concrete socket path, and on how each method behaves across Linux, macOS, and FreeBSD in CI pipelines.
Which approach yields stronger isolation when the client library only reads standard environment variables? How do socket permission models differ across distributions and affect test flakiness? What verification steps can confirm that no credentials appear in process environments or logs after test execution?