SECURITY / A CONCEPT NOTE
Secrets Management
storing and rotating API keys, passwords, and certificates safely
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
A secrets manager (Vault, AWS Secrets Manager, GCP Secret Manager) stores encrypted secrets and serves them on demand via API. Access is controlled by IAM policies. Secrets are never in code, config files, or environment variables at rest — they're fetched at runtime and rotated automatically.
02 / FOLLOW THE MECHANISM
How an app fetches a secret
App
starts up and authenticates to the secrets manager using its IAM role or a short-lived token.
Secrets manager
validates the identity, checks authorization policies, and audits the request.
Secrets manager
decrypts the secret value and returns it over TLS to the app.
App
caches the secret in memory (not disk) and uses it for the duration of its validity.
Rotation
a scheduled function or Vault plugin generates a new credential, updates both the secret store and the target service (DB, API).
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
fetch a secret from Vault
vault kv get secret/my-app/dbget a secret from AWS Secrets Manager
aws secretsmanager get-secret-value --secret-id prod/db/password05 / CHECK YOURSELF
Could you explain Secrets Management to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Security & identityCORSthe browser's same-origin policiy enforcer