[{"data":1,"prerenderedAt":1182},["ShallowReactive",2],{"content-en-\u002Fguide\u002Fphilosophy":3},{"id":4,"title":5,"body":6,"description":1173,"extension":1174,"jsonLd":1175,"meta":1176,"navigation":1177,"path":1178,"schemaRole":1175,"seo":1179,"stem":1180,"__hash__":1181},"content_en\u002Fguide\u002Fphilosophy.md","Development and Design Philosophy",{"type":7,"value":8,"toc":1160},"minimark",[9,13,22,28,33,43,51,54,64,67,83,86,93,109,112,115,118,157,160,163,179,182,186,195,198,201,204,207,210,216,226,229,240,243,254,261,267,271,274,280,287,290,297,303,309,315,318,326,332,341,347,350,357,363,367,370,373,378,381,388,394,400,403,406,409,415,419,422,428,431,451,454,457,460,463,466,469,480,483,489,492,495,500,517,526,536,543,549,555,568,572,575,602,605,611,614,617,620,623,626,633,636,642,648,654,660,663,668,671,677,680,688,694,700,703,730,733,736,739,745,756,760,763,769,772,778,781,797,800,803,806,813,817,820,823,826,833,836,839,842,845,848,851,854,857,861,864,871,877,880,883,886,896,899,902,905,909,912,915,918,921,927,930,936,942,945,951,954,957,960,966,972,987,990,993,996,999,1010,1013,1016,1026,1034,1042,1053,1056,1059,1062,1065,1068,1071,1074,1077,1080,1086,1091,1094,1097,1100,1107,1112,1120,1126,1130,1135,1138,1150,1153,1156],[10,11,5],"h1",{"id":12},"development-and-design-philosophy",[14,15,16,17,21],"p",{},"If you arrived here looking for the ",[18,19,20],"code",{},"bwsf"," command, this content might not be necessary for you.",[14,23,24,25,27],{},"However, for those who aren't familiar, we'll document here what concept ",[18,26,20],{}," is based on and what motivated its development.",[29,30,32],"h2",{"id":31},"what-are-environment-variables","What Are Environment Variables?",[14,34,35,36,38,39,42],{},"Before discussing ",[18,37,20],{}," and ",[18,40,41],{},".env"," files, you need to understand what environment variables are.",[14,44,45,46,50],{},"Environment variables are ",[47,48,49],"strong",{},"variables maintained by the operating system",".",[14,52,53],{},"You might be thinking, \"What does that even mean?\"",[14,55,56,57,60,61,50],{},"A ",[47,58,59],{},"variable",", in computers and programming languages, is a ",[47,62,63],{},"container for values",[14,65,66],{},"For example, in the PHP programming language:",[68,69,74],"pre",{"className":70,"code":71,"language":72,"meta":73,"style":73},"language-php shiki shiki-themes github-dark-high-contrast","$value = \"Hello world\";\n","php","",[18,75,76],{"__ignoreMap":73},[77,78,81],"span",{"class":79,"line":80},"line",1,[77,82,71],{},[14,84,85],{},"This means the value \"value\" (the $ is a marker for variables) contains the string \"Hello world\" (assignment).",[14,87,88,89,92],{},"Therefore, when you execute this with PHP's ",[18,90,91],{},"echo"," command:",[68,94,96],{"className":70,"code":95,"language":72,"meta":73,"style":73},"echo $value;\n\u002F\u002F -> Hello world\n",[18,97,98,103],{"__ignoreMap":73},[77,99,100],{"class":79,"line":80},[77,101,102],{},"echo $value;\n",[77,104,106],{"class":79,"line":105},2,[77,107,108],{},"\u002F\u002F -> Hello world\n",[14,110,111],{},"\"Hello world\" is output.",[14,113,114],{},"The above is just a PHP example, and the syntax differs between programming languages, but the concept of variables is universal in the computer world.",[14,116,117],{},"Environment variables are not specific to programming languages—they're handled by the OS itself. While there are various operating systems, on Linux and macOS:",[68,119,123],{"className":120,"code":121,"language":122,"meta":73,"style":73},"language-bash shiki shiki-themes github-dark-high-contrast","export VALUE=\"Hello world\"\necho $VALUE\n# -> Hello world\n","bash",[18,124,125,142,150],{"__ignoreMap":73},[77,126,127,131,135,138],{"class":79,"line":80},[77,128,130],{"class":129},"sWyjQ","export",[77,132,134],{"class":133},"sMAXC"," VALUE",[77,136,137],{"class":129},"=",[77,139,141],{"class":140},"sTRMh","\"Hello world\"\n",[77,143,144,147],{"class":79,"line":105},[77,145,91],{"class":146},"sCcAr",[77,148,149],{"class":133}," $VALUE\n",[77,151,153],{"class":79,"line":152},3,[77,154,156],{"class":155},"sQrFR","# -> Hello world\n",[14,158,159],{},"This produces the output shown.",[14,161,162],{},"Environment variables have the following advantages and disadvantages:",[164,165,166,173],"ul",{},[167,168,169,172],"li",{},[47,170,171],{},"Advantage",": You can conceal content using variable names",[167,174,175,178],{},[47,176,177],{},"Disadvantage",": Since they're stored in memory, variable values are reset when you restart",[14,180,181],{},"These are the characteristics.",[29,183,185],{"id":184},"the-twelve-factor-app","The Twelve-Factor App",[14,187,188,189,50],{},"There's a concept called ",[190,191,185],"a",{"href":192,"rel":193},"https:\u002F\u002F12factor.net\u002F",[194],"nofollow",[14,196,197],{},"This is essentially a collection of best practices that have been shaped through years of web application development.",[14,199,200],{},"For example, Ruby on Rails broadly bases itself on this philosophy.",[14,202,203],{},"Ruby on Rails and other frameworks that inherit Rails' philosophy (like Laravel and Django) are also based on this thinking.",[14,205,206],{},"These so-called \"Rails way\" frameworks have been adopted by many products and operate stably.",[14,208,209],{},"In other words, The Twelve-Factor App is a very important way of thinking for developing robust web applications.",[14,211,212,213,50],{},"As the name suggests, it actually consists of ",[47,214,215],{},"12 factors",[14,217,218,219,50],{},"The third factor is ",[47,220,221],{},[190,222,225],{"href":223,"rel":224},"https:\u002F\u002F12factor.net\u002Fconfig",[194],"Config - Store config in the environment",[14,227,228],{},"While I encourage you to read the link for details, simply put:",[164,230,231,234,237],{},[167,232,233],{},"Database connection URLs",[167,235,236],{},"Usernames and passwords",[167,238,239],{},"API keys, etc.",[14,241,242],{},"This information should be managed using environment variables.",[14,244,245,246,249,250,253],{},"For example, if you write this in a configuration file like ",[18,247,248],{},"config.rb",", it will be recorded by ",[47,251,252],{},"VCS (Version Control System, with Git being the de facto standard today)",", which is indispensable in current application development.",[14,255,256,257,260],{},"Even if you're not using a public repository like GitHub, there's a risk that configuration values, passwords, and other ",[47,258,259],{},"sensitive information"," will remain in the version control system, be shared with other developers, and leak from there.",[14,262,263,264,50],{},"Therefore, The Twelve-Factor App established the principle that ",[47,265,266],{},"configuration values should be stored in environment variables",[29,268,270],{"id":269},"the-dotenv-approach","The dotenv Approach",[14,272,273],{},"However, as mentioned earlier, environment variables have unwieldy aspects.",[14,275,276,277,279],{},"You can't see the contents without outputting with the ",[18,278,91],{}," command, and you can't easily tell what environment variable names (key names) exist in the terminal.",[14,281,282,283,286],{},"There is a ",[18,284,285],{},"printenv"," command that can list them all, but conversely, it outputs all environment variables across the entire terminal, which can be unwieldy.",[14,288,289],{},"Furthermore, since the information disappears when the terminal is restarted, developing with environment variables has various hassles.",[14,291,292,293,296],{},"This is where the ",[18,294,295],{},"dotenv"," approach was born.",[14,298,299,300,302],{},"You place a ",[18,301,41],{}," file at the root of your development directory.",[14,304,305,306,308],{},"Next, you install a package called ",[18,307,295],{}," for your development language. These have been ported to various languages and are available for PHP\u002FNode.js\u002FPython\u002FRuby\u002FGo\u002FDocker, etc.",[14,310,311,312,314],{},"The ",[18,313,295],{}," package reads the .env file at your project root and exports the information written there as environment variables.",[14,316,317],{},"A typical .env file looks like:",[68,319,324],{"className":320,"code":322,"language":323,"meta":73},[321],"language-text","DATABASE_URL=postgres:\u002F\u002Fuser:password@db.example.com:5432\nDATABASE_USER=john\nDATABASE_PASSWORD=secretpassword\n","text",[18,325,322],{"__ignoreMap":73},[14,327,328,329,331],{},"This is similar to what you'd write when using ",[18,330,130],{}," on the command line.",[14,333,334,337,338,50],{},[47,335,336],{},"A very important point"," is that these ",[47,339,340],{},".env files should be excluded from version control systems",[14,342,343,344,346],{},"Because if you don't, configuration values will be version-controlled just like in the ",[18,345,248],{}," case.",[14,348,349],{},"In other words, it's important that .env files exist only on users' local machines.",[14,351,352,353,356],{},"With Git, you can exclude files from Git management by adding the following to your ",[18,354,355],{},".gitignore"," file:",[68,358,361],{"className":359,"code":360,"language":323,"meta":73},[321],".env\n",[18,362,360],{"__ignoreMap":73},[29,364,366],{"id":365},"multiple-developers-are-the-norm","Multiple Developers Are the Norm",[14,368,369],{},"Now, if you're developing alone, you can just save the .env file in your directory, but in modern software development, it's normal to work with multiple people.",[14,371,372],{},"This creates the need to share these .env files.",[14,374,375],{},[47,376,377],{},"But wait a moment.",[14,379,380],{},"Some of you may have already had this experience.",[14,382,383,384,387],{},"For example, have you ever \"",[47,385,386],{},"shared .env files via email\u002Fchat tools like Slack\u002Ffile sharing tools like Dropbox or Google Drive","\"?",[14,389,390,391,50],{},"This is a ",[47,392,393],{},"very dangerous practice",[14,395,396,397,50],{},"From The Twelve-Factor App perspective, configuration values are information that ",[47,398,399],{},"must be kept secret",[14,401,402],{},"However, with email they pile up in your inbox, and the same goes for Slack.",[14,404,405],{},"What about Dropbox or Google Drive? You might delete them later, but they remain as revisions.",[14,407,408],{},"Are you going to delete revisions every single time? That's tedious. What if you forget to delete them?",[14,410,411,412,50],{},"Thus, sharing .env files is ",[47,413,414],{},"the exact opposite of the best practice of keeping configuration values secret",[29,416,418],{"id":417},"the-problem-of-different-configuration-values-per-environment","The Problem of Different Configuration Values per Environment",[14,420,421],{},"At this point, engineers were already struggling, but an even more complex problem emerged.",[14,423,424,425,50],{},"It's the issue of ",[47,426,427],{},"different configuration values for different environments",[14,429,430],{},"Particularly in web system development, there are various development environments, but generally they're divided as follows:",[164,432,433,439,445],{},[167,434,435,438],{},[47,436,437],{},"Local development environment",": The environment where developers work on their PCs\u002FMacs",[167,440,441,444],{},[47,442,443],{},"Staging environment",": An environment that reproduces what was developed in the same state as production (on the cloud)",[167,446,447,450],{},[47,448,449],{},"Production environment",": Also called the live environment. The environment actually serving business or solutions",[14,452,453],{},"Depending on the development site, this may further split into multiple development environments, but this is generally the common structure.",[14,455,456],{},"However, these environments are all built as separate environments. Otherwise, it would be meaningless.",[14,458,459],{},"For example, the staging environment exists to test systems built by multiple developers in a production-like situation, but it must be separate from the production environment.",[14,461,462],{},"Otherwise, if a bug occurs in production, it could negatively impact the production environment that's running as a business or solution.",[14,464,465],{},"Therefore, connection information for servers and databases differs for each environment.",[14,467,468],{},"Using the earlier example, locally it would be:",[68,470,474],{"className":471,"code":472,"language":473,"meta":73,"style":73},"language-txt shiki shiki-themes github-dark-high-contrast","DATABASE_URL=postgres:\u002F\u002Fuser:password@localhost:5432\n","txt",[18,475,476],{"__ignoreMap":73},[77,477,478],{"class":79,"line":80},[77,479,472],{},[14,481,482],{},"But for staging:",[68,484,487],{"className":485,"code":486,"language":323},[321],"DATABASE_URL=postgres:\u002F\u002Fuser:password@staging.example.com:5432\n",[18,488,486],{"__ignoreMap":73},[14,490,491],{},"And a production version is also needed.",[14,493,494],{},"Thus, the environment variable name (key) is the same, but the value changes depending on the environment.",[14,496,497,499],{},[18,498,295],{}," takes the following approach to this:",[164,501,502,507,512],{},[167,503,504],{},[18,505,506],{},".env.local",[167,508,509],{},[18,510,511],{},".env.staging",[167,513,514],{},[18,515,516],{},".env.production",[14,518,519,520,522,523,525],{},"Instead of just ",[18,521,41],{},", you add a ",[18,524,50],{}," followed by the environment name.",[14,527,528,529,532,533,50],{},"The environment names above are general examples—projects may also have ",[18,530,531],{},".env.develop"," or ",[18,534,535],{},".env.test",[14,537,538,539,542],{},"However, what's common is that ",[18,540,541],{},".env.your_environment_name"," should not be included in version control.",[14,544,545,546,548],{},"So how should you write ",[18,547,355],{},"? Like this:",[68,550,553],{"className":551,"code":552,"language":323},[321],".env\n.env.*\n",[18,554,552],{"__ignoreMap":73},[14,556,557,558,561,562,38,564,567],{},"The asterisk (*) is a wildcard, meaning it matches any string after ",[18,559,560],{},".env.",".\nThat is, files named ",[18,563,41],{},[18,565,566],{},".env.(any string here)"," are excluded from Git.",[29,569,571],{"id":570},"too-much-sensitive-information-in-modern-times","Too Much Sensitive Information in Modern Times",[14,573,574],{},"Now, we've learned many things so far:",[164,576,577,582,587,592,597],{},[167,578,579],{},[47,580,581],{},"Keep configuration values secret with environment variables",[167,583,584],{},[47,585,586],{},"Use dotenv and .env files to manage environment variables in files",[167,588,589],{},[47,590,591],{},"However, sharing via email, chat, or file sharing services is dangerous",[167,593,594],{},[47,595,596],{},".env files should not be included in version control systems like Git",[167,598,599],{},[47,600,601],{},"Create multiple .env files for each environment, like .env.staging",[14,603,604],{},"Even more challenges emerge.",[14,606,607,608,50],{},"The problem of ",[47,609,610],{},"too many configuration values",[14,612,613],{},"In the earlier example, we only defined one database URL, but in actual development environments, you handle many more environment variables.",[14,615,616],{},"It's common to work with multiple servers in parallel, and you might add faster key-value databases for caching.",[14,618,619],{},"Each of these has URLs, usernames, and passwords.",[14,621,622],{},"Configuration values quickly grow to 10, 20, and more.",[14,624,625],{},"It becomes hard to know what each configuration value name means.",[14,627,628,629,632],{},"In .env, if you prefix a line with ",[18,630,631],{},"#",", it automatically becomes a comment.",[14,634,635],{},"However, the challenge of sharing .env files themselves remains.",[14,637,292,638,641],{},[18,639,640],{},".env.example"," approach was conceived.",[10,643,645,646],{"id":644},"writing-envexample","Writing ",[18,647,640],{},[14,649,650,651,653],{},"For example, let's say you write ",[18,652,41],{}," like this:",[68,655,658],{"className":656,"code":657,"language":323,"meta":73},[321],"# Main database URL. Using Postgres\nDATABASE_URL=postgres:\u002F\u002Fuser:password@localhost:5432\n",[18,659,657],{"__ignoreMap":73},[14,661,662],{},"This should work for the developer's local environment.",[14,664,665,666,50],{},"Then, prepare a file called ",[18,667,640],{},[14,669,670],{},"The contents are as follows:",[68,672,675],{"className":673,"code":674,"language":323,"meta":73},[321],"# Copy .env.example, rename it to .env, then replace the values before use\n# Main database URL. Using Postgres.\nDATABASE_URL=postgres:\u002F\u002Fsample_user_name:sample_password@example.com:5432\n",[18,676,674],{"__ignoreMap":73},[14,678,679],{},"How's that? It's clearly a sample, and the comments convey that you should modify and use it.",[14,681,682,683,50],{},"And importantly, ",[47,684,685,687],{},[18,686,640],{}," can be managed in version control systems like Git",[14,689,690,691,50],{},"Since \"example\" means it's a sample, the values written there must only be ",[47,692,693],{},"samples",[14,695,696,697,699],{},"However, the variable names (key names) are the same as ",[18,698,41],{},", so developers can see what environment variable names are available.",[14,701,702],{},"If you're preparing .env files for each environment, it would look like:",[164,704,705,708,714,717,722,725],{},[167,706,707],{},".env.local ← Not version controlled",[167,709,710,711],{},".env.local.example ← ",[47,712,713],{},"Version controlled",[167,715,716],{},".env.staging ← Not version controlled",[167,718,719,720],{},".env.staging.example ← ",[47,721,713],{},[167,723,724],{},".env.production ← Not version controlled",[167,726,727,728],{},".env.production.example ← ",[47,729,713],{},[14,731,732],{},"It's confusing, but this is a very important point.",[14,734,735],{},"So how do you version control only .example files?",[14,737,738],{},"In .gitignore, you write:",[68,740,743],{"className":741,"code":742,"language":323,"meta":73},[321],".env\n.env.*\n!.env.example\n!.env.*.example\n",[18,744,742],{"__ignoreMap":73},[14,746,747,748,751,752,755],{},"This is how it looks. In .gitignore, when a line starts with ",[18,749,750],{},"!",", that line's specification is negated. It's confusing, but it means \"",[47,753,754],{},"ignore the item that ignores version control = version control it","\".",[29,757,759],{"id":758},"this-env-chaos-must-be-fixed","This .env Chaos Must Be Fixed",[14,761,762],{},"The situation up to this point, based on my personal experience, already existed around the mid-2010s.",[14,764,765,766,50],{},"But even though we've efficiently built up the logic—environment variables → .env → environment-specific .env → the invention of .example → using .gitignore—we still haven't fundamentally solved the challenge of ",[47,767,768],{},"securely transmitting the environment variables themselves",[14,770,771],{},"Conversely, this challenge has been addressed from the mid-2010s to now through ad-hoc solutions by individual teams and developers, each with their own style.",[14,773,774,775,50],{},"In other words, it's been improvised, and there's no best practice that can be called ",[47,776,777],{},"the standard",[14,779,780],{},"Of course, there are approaches to solve this:",[164,782,783,790],{},[167,784,785],{},[190,786,789],{"href":787,"rel":788},"https:\u002F\u002Faws.amazon.com\u002Fsystems-manager\u002F",[194],"AWS SSM",[167,791,792],{},[190,793,796],{"href":794,"rel":795},"https:\u002F\u002Fcloud.google.com\u002Fsecurity\u002Fproducts\u002Fsecret-manager",[194],"Google Secret Manager",[14,798,799],{},"These exist.",[14,801,802],{},"However, these tools have a strong flavor of being for managing environment variables to run production environments on AWS or GCP.",[14,804,805],{},"Also, since AWS and GCP have extensive services, managing account permissions requires careful attention.",[14,807,808,809,812],{},"In other words, they tend to be services where ",[47,810,811],{},"managing the management"," becomes a relatively large burden. (Clearly excessive just for .env management)",[29,814,816],{"id":815},"revisiting-env-file-transmission-methods","Revisiting .env File Transmission Methods",[14,818,819],{},"I can't speak to what the current industry standard is (since I mostly work on in-house services), but my image of .env files was that when you join a project, they're sent to you via chat from your supervisor or senior colleagues.",[14,821,822],{},"This might still be the case somewhere.",[14,824,825],{},"In my experience, when I receive information via chat, I delete it after receiving it, but I don't really know if it's truly deleted.",[14,827,828,829,755],{},"For example, with chat tools like Slack or Chatwork, when you press the \"delete\" button to delete this information, it shows something like \"",[830,831,832],"em",{},"This message was deleted",[14,834,835],{},"Engineers who know better think, \"Isn't that a soft delete?\"",[14,837,838],{},"Even if it truly is a hard delete, you're temporarily storing sensitive information on Slack or Chatwork's servers.",[14,840,841],{},"If your development NDA stipulates that confidential information cannot be placed on third-party servers, this is a serious problem.",[14,843,844],{},"Send it via email? Out of the question. Email can be intercepted, so you should never do this.",[14,846,847],{},"Pass it on an encrypted USB drive? That's quite a retro method, but it's difficult in the age of remote work. Actually, it's a bit of a hassle even on the same floor. Many offices prohibit USB drives anyway.",[14,849,850],{},"The most secure method is to write it on a sticky note in the same office, hand it over, write it into .env, and then shred the note.",[14,852,853],{},"Hmm, is this like the 20th century?",[14,855,856],{},"So, as you can see, methods for securely sending environment variables are all still risky.",[10,858,860],{"id":859},"easier-transmission-and-management","Easier Transmission and Management",[14,862,863],{},"I apologize for not having a decisive solution for transmission, but some of you reading this far may have noticed:",[14,865,866,867,870],{},"\"This is ",[47,868,869],{},"not just a transmission problem, but management is super difficult"," too, right?\"",[14,872,873,874],{},"Yes. ",[47,875,876],{},"Exactly!",[14,878,879],{},"Different files for each environment, and there are multiple of them.",[14,881,882],{},"Also, environment variables tend to increase in number as development progresses.",[14,884,885],{},"Also, environment variable values sometimes change for various reasons.",[14,887,888,889,892,893,895],{},"One day you ",[18,890,891],{},"git pull"," and there's a new variable added to ",[18,894,640],{},", and you have to ask someone for the new value.",[14,897,898],{},"This situation occurs.",[14,900,901],{},"It's not just transmission. When updated, you have to resend the new information repeatedly or rewrite it.",[14,903,904],{},"AWS SSM and GCP Secret Manager do consider these aspects, but as mentioned, they're somewhat excessive services.",[10,906,908],{"id":907},"we-must-manage-environment-variables-in-the-cloud-but-safely","We Must Manage Environment Variables in the Cloud (But Safely)",[14,910,911],{},"If you've read this far carefully, you should understand how important configuration values are and how they should be kept secret.",[14,913,914],{},"On the other hand, there's the current challenge of having to proceed with a system like .env, which can be managed locally but has many tedious issues.",[14,916,917],{},"So our idea is that .env should be managed not just locally, but in the cloud (remotely).",[14,919,920],{},"Since both AWS and GCP effectively manage in the cloud, managing environment variables ≠ cloud is NG.",[14,922,923,924,50],{},"One important thing is that ",[47,925,926],{},"managing environment variables in plaintext in the cloud is NG",[14,928,929],{},"Of course, it would be nice if we could manage locally only, but that has already reached its limits.",[14,931,932,933,50],{},"So the question becomes how to ",[47,934,935],{},"safely manage environment variables in the cloud",[14,937,938,939,50],{},"The answer is ",[47,940,941],{},"strong encryption",[14,943,944],{},"Actually, some chat and file sharing services already implement E2E encryption.\nIf so, sending → hard delete (if it truly is a hard delete) might be okay.",[14,946,947,948,50],{},"However, this doesn't fulfill the goal of ",[47,949,950],{},"conveniently managing environment variables",[14,952,953],{},"Should you send to the team chat every time the .env.example file changes, and have the leader manually delete it a few hours later?",[14,955,956],{},"Should development members manually copy and paste from chat and overwrite .env?",[14,958,959],{},"In this day and age, that's a bit nonsensical.",[14,961,962,963,965],{},"So, in developing ",[18,964,20],{},", we created the following concept.",[29,967,969,971],{"id":968},"bwsf-development-concept",[18,970,20],{}," Development Concept",[973,974,975,978,981,984],"ol",{},[167,976,977],{},"Environment variables are managed in the cloud (remotely) (however, with strong encryption)",[167,979,980],{},"Environment variables can be applied to local environments via CLI",[167,982,983],{},"Environment variables can be sent to the cloud (remotely) via CLI",[167,985,986],{},".example files are excluded and should be Git-managed",[14,988,989],{},"These are concepts, but we considered detailed tech stacks for implementation.",[14,991,992],{},"Especially, what's the best approach for storing environment variables in the \"cloud\"? We thought about various options.",[14,994,995],{},"First, a managed SaaS was an initial strong option that came to mind.",[14,997,998],{},"However, important considerations quickly emerged that forced us to exclude it:",[164,1000,1001,1004,1007],{},[167,1002,1003],{},"What happens if that service ends?",[167,1005,1006],{},"Is the encryption strength sufficient?",[167,1008,1009],{},"There's a possibility of being affected by specification changes",[14,1011,1012],{},"On the other hand, self-developing a secure backend service also takes considerable effort.",[14,1014,1015],{},"Also, bwsf's purpose is to simplify .env management, not to create open-source secure storage.",[14,1017,1018,1019,1022,1023,50],{},"So we decided to use something existing for the backend—specifically something that has ",[47,1020,1021],{},"some flexibility in how data is structured"," and has ",[47,1024,1025],{},"high encryption strength",[14,1027,1028,1029,50],{},"What was ultimately adopted is ",[190,1030,1033],{"href":1031,"rel":1032},"https:\u002F\u002Fbitwarden.com\u002F",[194],"Bitwarden",[14,1035,1036,1037,50],{},"Bitwarden is a password manager that is also available as ",[190,1038,1041],{"href":1039,"rel":1040},"https:\u002F\u002Fbitwarden.com\u002Fopen-source\u002F",[194],"open source",[14,1043,1044,1045,1048,1049,1052],{},"Regarding encryption, it uses ",[47,1046,1047],{},"AES-256"," with ",[47,1050,1051],{},"600,000 PBKDF2 iterations",", which we considered sufficient for our requirements.",[14,1054,1055],{},"Next, functionality.",[14,1057,1058],{},"Basically, Bitwarden is a password manager, so it's designed to easily store login items (ID, password, TOTP), etc.",[14,1060,1061],{},"On the other hand, it can also store information other than passwords (such as credit card information or ID images).",[14,1063,1064],{},"What we focused on was the \"Secure Note\" format.",[14,1066,1067],{},"This is stored in a very simple blog-like format with a title and body text.",[14,1069,1070],{},"We decided to store the \"project name\" in the title and the .env file contents in JSON format in the \"note body\".",[14,1072,1073],{},"Also, Bitwarden has a concept of \"organizations\", and you can grant access permissions to users associated with that \"organization\".",[14,1075,1076],{},"This means you can allow only specific developers to access only specific project bwsf\u002FBitwarden note items.",[14,1078,1079],{},"If a member leaves the development team, you just need to remove them on Bitwarden.",[14,1081,1082,1083,50],{},"Also, as mentioned earlier, ",[47,1084,1085],{},"Bitwarden is open source",[14,1087,1088,1090],{},[18,1089,20],{}," itself can be used with the cloud version of Bitwarden, but of course it can also be used with the open-source version.",[14,1092,1093],{},"This is very effective when there's a requirement not to place confidential information on third-party servers.",[14,1095,1096],{},"You can host Bitwarden on your own on-premises server or VPS and manage it there.",[14,1098,1099],{},"This is a requirement that even AWS SSM or Google Secret Manager cannot fulfill.",[14,1101,1102,1103,1106],{},"The existence of the ",[18,1104,1105],{},"bw"," command was also significant.",[14,1108,311,1109,1111],{},[18,1110,1105],{}," command is Bitwarden's CLI, and while not all features are available, you can perform typical Bitwarden operations from the command line.",[14,1113,1114,1116,1117,1119],{},[18,1115,20],{}," currently depends on the ",[18,1118,1105],{}," command for features like login.",[14,1121,1122,1123,1125],{},"However, thanks to this, we were able to develop ",[18,1124,20],{}," quickly.",[29,1127,1129],{"id":1128},"in-closing","In Closing",[14,1131,1132,1134],{},[18,1133,20],{}," is still in development. There are many features we still want to add.",[14,1136,1137],{},"We extend our deep gratitude to Bitwarden and the Bitwarden open-source community for allowing us to develop with almost no backend development needed.",[14,1139,1140,1141,1143,1144,1149],{},"Also, if you see potential in ",[18,1142,20],{}," and would like to help with development, you're always welcome. Please read the ",[190,1145,1148],{"href":1146,"rel":1147},"https:\u002F\u002Fgithub.com\u002Fb4m-oss\u002Fbwsf\u002Fblob\u002Fmain\u002FCONTRIBUTING.md",[194],"Contributing Guidelines"," and join us.",[1151,1152],"hr",{},[14,1154,1155],{},"Kohki SHIKATA, CEO of Bicycle for Mind LLC\nDec 1st 2025",[1157,1158,1159],"style",{},"html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html pre.shiki code .sWyjQ, html code.shiki .sWyjQ{--shiki-default:#FF9492}html pre.shiki code .sMAXC, html code.shiki .sMAXC{--shiki-default:#F0F3F6}html pre.shiki code .sTRMh, html code.shiki .sTRMh{--shiki-default:#ADDCFF}html pre.shiki code .sCcAr, html code.shiki .sCcAr{--shiki-default:#91CBFF}html pre.shiki code .sQrFR, html code.shiki .sQrFR{--shiki-default:#BDC4CC}",{"title":73,"searchDepth":105,"depth":105,"links":1161},[1162,1163,1164,1165,1166,1167,1168,1169,1170,1172],{"id":31,"depth":105,"text":32},{"id":184,"depth":105,"text":185},{"id":269,"depth":105,"text":270},{"id":365,"depth":105,"text":366},{"id":417,"depth":105,"text":418},{"id":570,"depth":105,"text":571},{"id":758,"depth":105,"text":759},{"id":815,"depth":105,"text":816},{"id":968,"depth":105,"text":1171},"bwsf Development Concept",{"id":1128,"depth":105,"text":1129},"If you arrived here looking for the bwsf command, this content might not be necessary for you.","md",null,{},true,"\u002Fguide\u002Fphilosophy",{"title":5,"description":1173},"guide\u002Fphilosophy","KJunxzx7KUQ7rECoGm2AILMJGtve4OFN2itoxSSaVUo",1788146015982]