How to protect referenced secrets from being seen

Hi @watsonian,

I guess, since the not so secrete config discussion I’m running the thought experiment to store all env variables in Doppler.

Developers - for the projects they manage - should be free to add new ENV variables to the production configs, but things like database passwords are not managed by them and should not be accessible to them.

Hope this helps.