I want to avoid using a clear text password in my deployment project.
I have several interactions with the application server via curl. I created a service account on the app server and need to provide the password via http basic authentication.
So my script task in the bamboo deployment project calls curl -u and includes a variable containing the service account user:pass.
However, the service account password is visible to anyone who has access to the variables configuration screen on the environment. I want to make sure someone with root access to the bamboo server, admin access in bamboo, and full access to the code cannot retrieve this service account password.
Do I have any options to prevent any access to the service account password?