# MySQL username and password protection

**URL:** <https://forum.ghost.org/t/mysql-username-and-password-protection/19962>\
**Category:** Using Ghost\
**Created:** [February 4, 2021, 11:35am UTC](https://forum.ghost.org/t/mysql-username-and-password-protection/19962 "2021-02-04T11:35:54Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lekeffrt4](https://avatars.discourse-cdn.com/v4/letter/l/bc8723/32.png) [@Lekeffrt4](https://forum.ghost.org/u/Lekeffrt4)\
**Post date:** [February 4, 2021, 11:35am UTC](https://forum.ghost.org/t/mysql-username-and-password-protection/19962/1 "2021-02-04T11:35:54Z")

</div>

Hi,

I want to put MySQL login credentials in config.production.json file. Username and password are stored in plain text though.

How to protect it?

Can I fetch data from docker secrets to the json file, maybe?

---

<div class="post-metadata">

**Author:** ![Kevin](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/kevin/32/32_2.png) [@Kevin](https://forum.ghost.org/u/Kevin)\
**Post date:** [February 4, 2021, 11:55am UTC](https://forum.ghost.org/t/mysql-username-and-password-protection/19962/2 "2021-02-04T11:55:00Z")

</div>

You can pass config in with env variables if you don’t want to store credentials in files [https://ghost.org/docs/config/#running-ghost-with-config-env-variables](https://ghost.org/docs/config/#running-ghost-with-config-env-variables)
