Skip to content
EduVerse

Secrets Management

Explained

Concept

Also known as: Secrets

Securely storing and distributing sensitive configuration such as API keys, passwords and certificates.

Secrets Management, explained

Written by EduVerse

What it is

Secrets management is the practice of keeping sensitive values, like database passwords, API keys and private certificates, out of your code and storing them somewhere safe. Applications receive them at runtime through environment variables or a dedicated store such as HashiCorp Vault, AWS Secrets Manager or your CI platform’s secret settings.

Why teams use it

Anything committed to Git stays in its history, can end up in forks and is visible to everyone with access to the repository. A leaked key can cost money or expose customer data. Central secret storage also lets you replace a key in one place and control who can read it.

An example from work

You’re about to commit and notice your .env file with a real Stripe key in the list of staged files. You unstage it, add .env to .gitignore and commit a .env.example with empty values instead. In the pipeline, the real key comes from the CI provider’s secret settings.

Our own explanation, not a quote from the book.

In the book

Sentences from The Software Realm, Decoded that mention Secrets Management, exactly as printed.

    1 more passages about Secrets Management in the full book

    Read every conversation where Secrets Management comes up, with the interactive slides and demos.

    See the book

    Where it fits

    Protecting credentials in CI/CD and production

    Coverage in the book

    Explained

    Explained and compared with alternatives, so you know where and why it’s used.

    Appears in