Automation Pipeline4 min read

Every channel I added came with another secret file

I built a pipeline for Korean and English YouTube channels that turn devlog posts into videos. Before the branding, upload, and analytics scripts, one .gitignore line needed attention. Each channel gets its own token file, so ignoring a single filename wasn't enough.

#youtube#gitignore#oauth#secrets#pipeline
Left: a .gitignore listing a single token filename, with new token files piling up below it as channels are added. Right: one yt_token*.json pattern covering every token file.
Every channel I added came with another secret file.

Two channels, three scripts

I decided to publish my devlog posts as videos too, on two channels: one Korean, one English. It went in as one commit: four files, 226 lines.

  • devlog_channel.py sets channel branding through the API, separately for the ko and en channels.
  • devlog_upload.py uploads the mp4 and its metadata, then posts the blog link as the first comment.
  • devlog_analytics.py pulls views, retention, and subscriber changes for each video on these channels.
  • .gitignore gets one wildcard line: yt_token*.json.

The three scripts were the work I expected. This post is about the fourth line. A question first: does your .gitignore block the secret files you have now, or also the ones you'll create later?

Videos weren't the only thing multiplying

The YouTube Data API runs on OAuth tokens, and you get a separate token for each channel. With one channel there's one token file, so ignoring that one filename seems like enough.

Add channels and the token files multiply too. The Korean channel, the English channel, and the channel I already had each get a file starting with yt_token. If .gitignore names only one exact file, the new tokens aren't covered. One git add . and a new token is staged.

What makes this tricky is that nothing fails. Uploads work, branding gets applied, analytics returns numbers. The whole pipeline can be green while an extra secret file sits in the commit.

What would you do?

Would you add another filename to .gitignore for every new channel, or set a naming rule and block it with one pattern?

I blocked the rule, not the name

I went with a pattern. Every token file starts with yt_token, and .gitignore has one line: yt_token*.json. Whether there are three channels or five, the only thing to keep is the naming rule.

This has two caveats.

First, it only works if the naming rule holds. If someone (usually me, months from now) saves a token as token_en.json, the pattern misses it. A wildcard only protects you if you follow the convention.

Second, .gitignore does nothing for files git already tracks. If a token file was ever committed, adding it to the ignore list won't stop git from tracking it. You'd need git rm --cached to untrack it, and then you'd need to reissue the token.

The other two scripts follow the same idea

I scripted branding through the API instead of clicking through the Studio UI for the same reason: there are two channels. Setting them up by hand makes them drift apart. In code, ko and en go through the same steps.

Posting the blog link as the first comment happens inside the upload script. If it's a separate step after uploading, it eventually gets skipped.

The analytics script went into the same commit as the upload script. If you write the measurement code after videos start going up, the first few days usually go by with no numbers.

Self-check

  • Does each new account or channel create another secret file? If so, check that .gitignore blocks the naming pattern, not one filename.
  • Does git ls-files | grep -i token come back empty? .gitignore doesn't remove files git already tracks.
  • Does the code that writes new secret files enforce the naming rule, or does a person pick the name each time?

The honest part

All this commit records is that the wildcard was added. It doesn't say whether the old .gitignore listed one exact token filename, or whether a token ever came close to being committed. So the risk described here is what this setup allows, not an incident I actually had. The analytics script was only written at this point, and this record has no views or retention numbers for either channel. I also haven't checked whether the branding API can cover every Studio setting.

Related