Right now our connection strings sit in appsettings.json as plain text, and I'm worried about secrets leaking into source control or container images. We're not ready to adopt Azure Key Vault because the team wants to keep dependencies light.
What's the most practical approach for a small ASP.NET Core API using Dapper? I've heard about User Secrets for local development and environment variables for staging, but I'm unsure how to wire that cleanly into IConfiguration without scattering GetConnectionString calls everywhere. Is there a standard helper or pattern you'd recommend?
Can you answer this question?
Write Answer0 Answers