Secrets Management
ExplainedConcept
Also known as: Secrets
Securely storing and distributing sensitive configuration such as API keys, passwords and certificates.
Secrets Management, explained
Written by EduVerseWhat it is
Secrets management is the practice of keeping sensitive values, like database passwords, API keys and private certificates, out of your code and storing them somewhere safe. Applications receive them at runtime through environment variables or a dedicated store such as HashiCorp Vault, AWS Secrets Manager or your CI platform’s secret settings.
Why teams use it
Anything committed to Git stays in its history, can end up in forks and is visible to everyone with access to the repository. A leaked key can cost money or expose customer data. Central secret storage also lets you replace a key in one place and control who can read it.
An example from work
You’re about to commit and notice your .env file with a real Stripe key in the list of staged files. You unstage it, add .env to .gitignore and commit a .env.example with empty values instead. In the pipeline, the real key comes from the CI provider’s secret settings.
Our own explanation, not a quote from the book.
In the book
Sentences from The Software Realm, Decoded that mention Secrets Management, exactly as printed.
1 more passages about Secrets Management in the full book
Read every conversation where Secrets Management comes up, with the interactive slides and demos.
Where it fits
Protecting credentials in CI/CD and production
Coverage in the book
Explained and compared with alternatives, so you know where and why it’s used.