NOTE
This file was generated by Descript <www.descript.com>
1

00:00:01,410  -->  00:00:03,030
Hi guys, and welcome back.

2

00:00:03,060  -->  00:00:06,600
In this video, we're going to learn how
to deal with secrets, or things that

3

00:00:06,600  -->  00:00:12,090
we don't want to put in our code, but
that our code needs in order to run.

4

00:00:12,600  -->  00:00:17,220
The only secret that we've got in this
code at the moment is the MongoDB URI.

5

00:00:17,790  -->  00:00:21,736
And that is this in here more
specifically, we've gone three secrets,

6

00:00:21,976  -->  00:00:28,066
those are the username, the password, and
the server name of the MongoDB cluster.

7

00:00:28,396  -->  00:00:33,106
So we can keep this a secret
by hiding it from our code.

8

00:00:33,406  -->  00:00:36,346
But obviously I mentioned that the
code needs it in order to work.

9

00:00:36,346  -->  00:00:40,096
So we do need to do a little bit
of work in order to hide this,

10

00:00:40,186  -->  00:00:41,536
but still be able to use it.

11

00:00:42,046  -->  00:00:45,526
We're going to make use of environment
variables in order to do that.

12

00:00:46,026  -->  00:00:51,336
An environment variable is a variable
that is available to the running process.

13

00:00:51,541  -->  00:00:55,641
So when we run our Python app,
that Python app will have access

14

00:00:55,761  -->  00:00:59,601
to the environment variables that
have been set before running.

15

00:01:00,201  -->  00:01:06,091
We can also create environment variables
during the code run, and populate it,

16

00:01:06,261  -->  00:01:09,111
and the rest of the code will then have
access to those environment variables.

17

00:01:09,111  -->  00:01:12,951
If we want, you can think of
them as somewhat global variables

18

00:01:13,221  -->  00:01:15,321
that are not stored in the code.

19

00:01:15,919  -->  00:01:18,259
So, how do we create the
environment variables?

20

00:01:18,379  -->  00:01:21,019
The first thing we have to do
is we have to install a library.

21

00:01:21,019  -->  00:01:25,969
So I'm going to do pip install python
dash dotenv, and that is going to

22

00:01:25,969  -->  00:01:28,779
install this library there that we need.

23

00:01:29,499  -->  00:01:35,769
And then we're going to create a dotenv
file a dotenv file is where we normally

24

00:01:35,769  -->  00:01:39,939
put any environment variables that
we want our code to have access to.

25

00:01:40,419  -->  00:01:45,309
In here, we're going to write
MongoDB underscore URI equal, and

26

00:01:45,309  -->  00:01:49,419
then we're going to copy this entire
string there, but not the quotation

27

00:01:49,419  -->  00:01:50,499
marks, we're going to copy that.

28

00:01:50,859  -->  00:01:51,759
And we're going to put it in there.

29

00:01:52,256  -->  00:01:55,046
Remember to not leave any
spaces or anything like that.

30

00:01:56,126  -->  00:01:57,926
This is our dotenv file.

31

00:01:58,316  -->  00:02:03,266
Now we can tell our app to look
at that dotenv file and load the

32

00:02:03,266  -->  00:02:07,046
contents as environment variables
that the rest of the code can use.

33

00:02:07,946  -->  00:02:10,046
So we do from dotenv.

34

00:02:10,136  -->  00:02:12,746
This is the library we've just
installed, python-dotenv, we're

35

00:02:13,196  -->  00:02:15,446
going to input load_dotenv.

36

00:02:15,971  -->  00:02:18,441
And then we're going to call load_dotenv.

37

00:02:18,881  -->  00:02:22,061
That is going to look at the dotenv
file, and it's going to create

38

00:02:22,061  -->  00:02:25,031
an environment variable for each
variable that's defined here.

39

00:02:25,271  -->  00:02:28,181
So then we will have access
to MongoDB underscore URI.

40

00:02:28,478  -->  00:02:31,538
And the value of that
variable will be this.

41

00:02:32,236  -->  00:02:36,106
Now you may wonder how does
that help us hide the secret?

42

00:02:36,226  -->  00:02:38,596
Is this not part of our code base?

43

00:02:39,076  -->  00:02:42,796
Well, we're not going to put
this file into GitHub, so

44

00:02:42,796  -->  00:02:44,086
it's going to remain hidden.

45

00:02:44,986  -->  00:02:46,606
So here's something that we can do.

46

00:02:46,876  -->  00:02:50,406
We can create another file that
I'm going to call dot gitignore.

47

00:02:51,106  -->  00:02:55,376
And that is going to make sure
that whenever we use git to add

48

00:02:55,406  -->  00:03:00,086
our files to GitHub, the dotenv
file is not included in that.

49

00:03:00,116  -->  00:03:03,686
And we just have to write .env in
here, and that is going to make

50

00:03:03,686  -->  00:03:05,336
sure to ignore the dotenv file.

51

00:03:05,836  -->  00:03:09,296
If we're  not usinggits, which we
haven't done so far, then this is

52

00:03:09,296  -->  00:03:10,406
not going to make a difference.

53

00:03:10,706  -->  00:03:13,796
But later on, this might make a difference
and this is how we keep it hidden.

54

00:03:15,406  -->  00:03:20,526
However, every developer that
writes code in this project needs

55

00:03:20,526  -->  00:03:24,876
to have a MongoDB URI set in
order to be able to run the app.

56

00:03:25,176  -->  00:03:29,881
So we do need to tell other
developers that this environment

57

00:03:29,881  -->  00:03:31,411
variable should exist.

58

00:03:31,591  -->  00:03:35,251
And we do that with another
file called dotenv dot example.

59

00:03:35,521  -->  00:03:39,241
And here we're going to write
MongoDB underscore URI equal and

60

00:03:39,241  -->  00:03:40,261
we're going to leave it blank.

61

00:03:40,651  -->  00:03:41,701
This is the convention.

62

00:03:41,911  -->  00:03:46,111
Whenever you see a project that
has a dotenv dot example file.

63

00:03:46,741  -->  00:03:49,771
You know, that you have to create
a dot and file that has these

64

00:03:49,771  -->  00:03:51,541
things and the values for them.

65

00:03:51,751  -->  00:03:54,511
And if you don't have those, then
you have to find them out somehow

66

00:03:54,541  -->  00:03:56,251
probably by asking your teammates.

67

00:03:56,761  -->  00:04:00,881
So that is something that we can
create and we will include dotenv

68

00:04:00,901  -->  00:04:03,151
dot example in our GitHub project.

69

00:04:03,851  -->  00:04:06,701
So now that we've got that and we've
loaded the environment variables, all we

70

00:04:06,701  -->  00:04:09,461
have to do here instead of putting this.

71

00:04:10,211  -->  00:04:16,008
As a string, we just do import os at
the top, import os forgot to do that.

72

00:04:16,698  -->  00:04:23,538
And then in here we do os dot environ
dot get MongoDB URI, just like that.

73

00:04:23,838  -->  00:04:26,448
And that is going to go into the
environment variables that are

74

00:04:26,448  -->  00:04:29,778
currently available, and it's
going to get MongoDB URI from them.

75

00:04:30,078  -->  00:04:33,548
And its value is going to
be used in MongoClient.

76

00:04:34,248  -->  00:04:35,928
There is one more problem.

77

00:04:36,078  -->  00:04:38,598
And that is that we've done
all this, which is great.

78

00:04:38,868  -->  00:04:41,598
We do have to update our Heroku project.

79

00:04:41,688  -->  00:04:42,558
So let's do that.

80

00:04:42,948  -->  00:04:49,113
We have to change requirements.txt
to include python dash dotenv, since

81

00:04:49,113  -->  00:04:54,513
that is something that we're now using
in our app, but we can't give Heroku

82

00:04:54,603  -->  00:04:59,043
our dotenv file because we shouldn't
put the dotenv file in GitHub, and

83

00:04:59,043  -->  00:05:01,053
Heroku is getting the code from GitHub.

84

00:05:01,233  -->  00:05:04,843
So let's first update
requirements.txt, and put the

85

00:05:04,843  -->  00:05:06,463
dotenv dot example file into GitHub.

86

00:05:06,483  -->  00:05:10,293
And then I'll show you how we can use
environment variables and Heroku anyway.

87

00:05:10,993  -->  00:05:14,633
So here I've got open the GitHub
project, and we're going to start

88

00:05:14,633  -->  00:05:16,403
off by adding a couple of files.

89

00:05:16,503  -->  00:05:19,853
We're going to add the dot
gitignore and dotenv dot example.

90

00:05:20,353  -->  00:05:23,533
At the moment, it seems that when
you drag these files, that start

91

00:05:23,533  -->  00:05:27,973
with a dot over here, it doesn't
quite read them successfully.

92

00:05:28,123  -->  00:05:30,853
So let's just grab this
path and go to choose.

93

00:05:30,853  -->  00:05:35,053
Our files may show that that's the
correct path in there, and then grab the

94

00:05:35,053  -->  00:05:37,273
gitignore and the dotenv dot example file.

95

00:05:37,513  -->  00:05:39,373
Do not grab the dotenv file.

96

00:05:39,493  -->  00:05:44,323
As soon as we don't want that in our code,
then we're going to commit the changes.

97

00:05:45,023  -->  00:05:50,183
So now when we come back later on, we'll
know that we need a MongoDB URI in a

98

00:05:50,183  -->  00:05:51,983
dotenv file in order to run this project.

99

00:05:52,013  -->  00:05:53,933
This is helpful for us in the future.

100

00:05:54,433  -->  00:05:56,933
The other thing that we have to
do is go to requirements.txt,

101

00:05:57,253  -->  00:05:59,873
change this and add python-dotenv.

102

00:05:59,893  -->  00:06:02,653
So we do Python dash dotenv
and we'll add it there.

103

00:06:02,683  -->  00:06:04,663
Then at the bottom, we're
going to commit changes.

104

00:06:05,315  -->  00:06:07,415
The next thing to do is go over to Heroku.

105

00:06:07,595  -->  00:06:10,925
And in the settings tab, we're
going to reveal the config vars,

106

00:06:11,075  -->  00:06:12,635
and we're going to add a new one.

107

00:06:12,695  -->  00:06:16,385
These are the environment variables
that our Heroku app is going to have

108

00:06:16,385  -->  00:06:18,665
access to when it runs our flask code.

109

00:06:18,995  -->  00:06:24,145
So we'll do MONGODB underscore URI, just
like that, in the value we're going to

110

00:06:24,145  -->  00:06:26,935
place our MongoDB connection string.

111

00:06:27,435  -->  00:06:28,675
So we've got that there.

112

00:06:28,705  -->  00:06:29,485
We can hide this.

113

00:06:29,545  -->  00:06:32,435
And remember the only people who
will have access to these config

114

00:06:32,455  -->  00:06:37,315
vars are the ones that you've added
to the collaborators in Heroku.

115

00:06:37,917  -->  00:06:42,327
So now we've got the updated code in
our GitHub project and we've got the

116

00:06:42,327  -->  00:06:44,257
environment variable set up in Heroku.

117

00:06:44,547  -->  00:06:48,537
We can come down to the deploy tab
and press manual deploy, and that

118

00:06:48,537  -->  00:06:50,367
is going to use this latest code.

119

00:06:50,818  -->  00:06:54,558
And literally, as I pressed that, I
remember that we forgot to update app.py.

120

00:06:54,838  -->  00:06:56,818
So we do need to do that as well.

121

00:06:57,088  -->  00:06:59,548
This is one of the problems when
you're doing these updates manually.

122

00:07:00,238  -->  00:07:04,048
So let's update app.py, I'm just
going to grab everything, edit this

123

00:07:04,048  -->  00:07:06,298
file and paste everything in there.

124

00:07:06,478  -->  00:07:09,708
Just make sure to add the environment
variable access and so forth.

125

00:07:09,708  -->  00:07:11,358
So we're gonna save that.

126

00:07:12,060  -->  00:07:14,370
And now we have the updated
code, so we can come back

127

00:07:14,370  -->  00:07:16,320
here and we can deploy again.

128

00:07:16,320  -->  00:07:22,150
So this is going to deploy, but it's still
going to use the hard-coded MongoDB URI.

129

00:07:22,440  -->  00:07:23,910
It's not going to use
the environment variable.

130

00:07:24,120  -->  00:07:25,500
So we need to deploy again.

131

00:07:25,710  -->  00:07:28,483
I'll just refresh this page,
and press on deploy again.

132

00:07:29,259  -->  00:07:30,449
So the deploy worked.

133

00:07:30,549  -->  00:07:33,939
Now when we go back to the URL, we
can refresh the page and it should

134

00:07:33,939  -->  00:07:36,159
all be working, which is fantastic.

135

00:07:36,339  -->  00:07:41,449
So now we're using the hidden environment
variable or config var as Heroku,

136

00:07:41,469  -->  00:07:45,939
calls it instead of hard coding the
MongoDB connection string in our code.

137

00:07:46,419  -->  00:07:49,509
However, that is one more thing
that we should be wary of.

138

00:07:50,012  -->  00:07:54,992
Let's go back to GitHub, and we're going
to go over to the code tab, and then we're

139

00:07:54,992  -->  00:07:57,252
going to click on any of these commits.

140

00:07:57,910  -->  00:08:02,740
You can see that GitHub keeps track of
the files that were added and when they

141

00:08:02,740  -->  00:08:05,320
were added and what we added to each file.

142

00:08:05,530  -->  00:08:10,955
So in GitHub's history we still have
the MongoDB connection string here.

143

00:08:11,345  -->  00:08:15,545
Even though it's not in the final
code, it is still somewhere in the

144

00:08:15,545  -->  00:08:17,735
history of changes we made to the code.

145

00:08:19,025  -->  00:08:21,785
So if we made this repository
public to share it with our

146

00:08:21,785  -->  00:08:23,825
employers, they would know.

147

00:08:24,125  -->  00:08:28,595
That we were not aware that this was still
public and that will not look good on you.

148

00:08:28,895  -->  00:08:33,905
So what you have to do is either create
a new public repository that does not

149

00:08:33,905  -->  00:08:37,565
have the history of this repository
so that this will not be available.

150

00:08:37,895  -->  00:08:43,445
Or you can go ahead and change
your MongoDB,Atlas user or password

151

00:08:43,535  -->  00:08:47,585
so that these are no longer
valid login details for you.

152

00:08:48,088  -->  00:08:49,918
If you do either of those
things, you'll be safe.

153

00:08:49,918  -->  00:08:52,438
And even though this is here,
that will be fine because the

154

00:08:52,438  -->  00:08:53,938
password will be incorrect.

155

00:08:54,438  -->  00:08:57,298
So just something to be aware
of when you're doing this, that

156

00:08:57,298  -->  00:08:58,698
GitHub keeps the whole history.

157

00:08:59,178  -->  00:09:01,938
And if you want to make this repository
public, you can do that in settings.

158

00:09:02,488  -->  00:09:05,488
And then none of the bottom, you
can change the visibility of the

159

00:09:05,488  -->  00:09:08,848
repository to public if you want,
but make sure to change your MongoDB

160

00:09:08,938  -->  00:09:13,678
password first, there are bots
trawling public GitHub repositories,

161

00:09:13,828  -->  00:09:18,058
searching for MongoDB connection
strings on to other secrets that may

162

00:09:18,058  -->  00:09:19,618
have been made public accidentally.

163

00:09:19,768  -->  00:09:21,748
So that's also something to be aware of.

164

00:09:22,648  -->  00:09:23,008
All right.

165

00:09:23,038  -->  00:09:24,448
Thank you guys for
joining me in this video.

166

00:09:24,478  -->  00:09:27,178
I hope you've enjoyed it, and I hope you
have enjoyed this section as a whole.

167

00:09:27,358  -->  00:09:31,048
Your app is now publicly available,
so you can share it with users or you

168

00:09:31,048  -->  00:09:32,578
can use it yourself from anywhere.

169

00:09:32,938  -->  00:09:33,928
Thanks for joining me again.

170

00:09:34,018  -->  00:09:35,428
And I'll see you in the next one.
