Skip to main content
Springwinter stores what it needs to sign you in and to assume the role again. It does not keep a copy of your application data, and it does not keep the temporary credentials used to call AWS.

Stored for the organization

The GitHub App id, the GitHub App private key, and the webhook secret are runtime configuration on the control plane. They are not columns on your connection.

Not stored

  • Temporary AWS keys from sts:AssumeRole.
  • GitHub installation access tokens. One is minted when a build starts and is not written down.
  • GitHub personal access tokens. The product does not ask for one.
  • The Aurora master password. Aurora stores it in Secrets Manager in your account. Springwinter reads it when you ask for the credentials and does not write it into the application database.
  • A cache password. The Valkey cache has no AUTH password. Clients in the project use TLS.
  • Log lines and metric datapoints. Those are read from CloudWatch when you open the page.

Environment variables

Values you set for a server, a worker, or a static site are written onto the ECS task definition or the CodeBuild project in your account. ECS stores container environment in plaintext. The Environment page reads that task definition. It does not read a Springwinter table. There is no separate secret store for these values. Springwinter does not put them in Secrets Manager for you. A create or a preview that is given variables passes them in the workflow run input, so the first task definition can be written. That run record is kept. A reviewer should treat a workflow run as something that can contain the values supplied for that deploy, even though the live copy is the task definition in your account. Parameter filtering on the application drops environment from request logs. The values are still in the task definition, and they can still be in the run input.

Database credentials

Aurora Serverless v2 manages the master password in Secrets Manager in your account (ManageMasterUserPassword). Springwinter does not choose a password, does not store one, and does not write DATABASE_URL into its database. When you open the credentials, Springwinter assumes the role and reads the secret. That read is on demand.

API tokens

An API token is an organization credential. The plaintext secret is shown once, when it is created. Springwinter stores SHA-256 of the secret and a short prefix so you can recognize the token in the list. A later request is accepted only when the hash matches. Revoking the token deletes that record. Later requests with the old secret are rejected.

Passwords and email codes

Passwords are stored as a bcrypt hash. The minimum length is 8 characters. A confirmation code and a password-reset code are 6 digits. Springwinter stores an HMAC-SHA256 of the code, not the code itself. The code expires in 10 minutes. Five wrong attempts invalidate it. The message that carries the code is email, and the code is the secret in that message. A person added to the organization receives a generated password by email and can change it after signing in.