k6 environment‑variable credential handling without built‑in secret redaction
0 reputation · 01 Jul 2022, 21:45 UTC
Goal: Execute k6 load‑test scripts that read credentials from environment variables so that no secret is stored in the script file, while running against a staging or mock integration that mirrors production behavior.
Concern: k6 injects variables into the JavaScript runtime but provides no automatic redaction; if a script unintentionally logs or outputs __ENV values, the credentials appear in test output, logs, or result files, exposing them to all virtual users.
Uncertainty: Teams must decide whether to rely solely on environment‑variable injection for credential handling in k6 or to supplement it with an external secrets manager (e.g., HashiCorp Vault, AWS Secrets Manager) and fetch secrets at runtime via an HTTP call, which k6 does not natively support.
- What are the practical risks of depending only on environment‑variable injection for credential security in k6?
- How can teams prevent accidental logging of __ENV values across all VUs without modifying each script?
- Is it feasible to integrate an external secrets manager within a k6 test flow without breaking the tool’s execution model?