I am trying to set up a CI/CD process for Salesforce using Docker and SFDX.
I got everything working except that I am not sure how to safely store the private key that SFDX uses to authenticate into salesforce.
Here's the command that I am using to authenticate:
sfdx force:auth:jwt:grant --clientid $CONSUMER_KEY --jwtkeyfile keys/server.key --username $SFDC_QA_USER --setdefaultdevhubusername --setalias testPipelines --instanceurl $SFDC_QA_URL
Where "CONSUMER_KEY" is a repository variable.
However server.key is inside a "keys" folder in the branch itself.
I was wondering if there's something like "repository secret files" maybe? If not can I store an encrypted version of the server.key and have docker decrypt it and pass it to SFDX? I am really not sure how to approach this.