Secrets Management
Runtime injection, dynamic credentials and rotation applications survive.
5 to work through
-
intermediate
A payments platform's secrets are in environment variables, set once at deployment. What is wrong, and what should replace it?
2 min answer -
intermediate
A team stores credentials in a secrets manager and considers the problem solved. What is still wrong, and what does a genuinely good secrets posture look like?
2 min answer -
advanced
A CI/CD platform runs untrusted code from external contributors and also holds deployment credentials. How should secrets be architected so a malicious pull request cannot exfiltrate them?
2 min answer -
advanced
An estate has database passwords in environment variables across 200 services. Design the migration to a secrets manager.
2 min answer -
advanced
You deploy a secrets manager. Every application now fetches its secrets from it. Security asks how the applications authenticate to the vault. What is the answer?
2 min answer
4 terms in this topic
Dynamic Secrets
Credentials generated on demand for a specific consumer with a short lease, rather than stored, shared and rotated periodically.
conceptSecret Zero
The credential a workload needs in order to authenticate to the secret manager — the one secret that cannot itself be stored in the secret manager.
conceptSecret Zero Problem
The credential a workload needs in order to authenticate to the secret manager, which cannot itself be stored in the secret manager.
conceptStanding Credential
A credential that remains valid indefinitely, so a single leak grants permanent access - the property that converts a small compromise into a large o…
Neighbouring topics
Security Architecture
General material on securing an architecture.
Authentication
Establishing who a principal is, and how strong that claim needs to be.
Authorization
RBAC, ABAC and ReBAC, and centralising the decision but not the enforcement.
OAuth 2.0 & OIDC
Delegated authorisation, and the identity layer that makes login safe.
Tokens & JWTs
Stateless validation, revocation, and pinning the algorithm.
Identity & Access Management
Workload identity, roles, permission boundaries and usage-based review.
Encryption
At rest, in transit, and at the application layer — three different threats.
Key Management
Rotation, separation of duty, envelope encryption and crypto-shredding.
Zero Trust
No implicit trust from network position; authorise every request.
Threat Modelling
Walking trust boundaries with STRIDE before anything is built.
OWASP Risks
The recurring web and API risk classes, several of which are design flaws.
Secure API Design
Object-level authorisation, input validation and safe error responses.
Supply Chain Security
Dependencies, SBOMs, build provenance and artefact signing.
Network Security
Segmentation, egress control and limiting lateral movement.
Auditability
Tamper-evident, attributed records that survive async boundaries.
Compliance Frameworks
SOC 2, ISO 27001, PCI DSS — scope as an architectural lever.
Privacy Engineering
Minimisation, purpose limitation, and erasure that is implementable.
Data Classification
Knowing which fields are regulated, because every control depends on it.
Security Incident Response
Detection, scoping, containment and notification clocks.