SECURITY / A CONCEPT NOTE

Secrets Management

storing and rotating API keys, passwords, and certificates safely

~75 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

A secrets manager (Vault, AWS Secrets Manager, GCP Secret Manager) stores encrypted secrets and serves them on demand via API. Access is controlled by IAM policies. Secrets are never in code, config files, or environment variables at rest — they're fetched at runtime and rotated automatically.

02 / FOLLOW THE MECHANISM

How an app fetches a secret

  1. App

    starts up and authenticates to the secrets manager using its IAM role or a short-lived token.

  2. Secrets manager

    validates the identity, checks authorization policies, and audits the request.

  3. Secrets manager

    decrypts the secret value and returns it over TLS to the app.

  4. App

    caches the secret in memory (not disk) and uses it for the duration of its validity.

  5. Rotation

    a scheduled function or Vault plugin generates a new credential, updates both the secret store and the target service (DB, API).

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · REFERENCE

fetch a secret from Vault

vault kv get secret/my-app/db

EXAMPLE 02 · REFERENCE

get a secret from AWS Secrets Manager

aws secretsmanager get-secret-value --secret-id prod/db/password

Explore command anatomy in the CLI lab