Lesson 12 / 25
Secrets Management
Keys and tokens outside code.
Store, rotate and scope secrets
API keys, database passwords and signing keys must not live in source code, images or client-side bundles. Store them in a secrets manager (cloud secret stores, HashiCorp Vault) or at least injected environment variables, grant each service only the secrets it needs, rotate them regularly and immediately after exposure, and prefer short-lived credentials (workload identity, OIDC federation) over static keys. Scan repositories and CI logs for leaked secrets.
Reading a secret at runtime
Python sketch; the secret value never appears in the repository.
import os
# VULNERABLE: committed to git forever
STRIPE_KEY = "sk_live_51H..."
# BETTER: injected at runtime by the platform or a secrets manager
STRIPE_KEY = os.environ["STRIPE_API_KEY"]
# Add secret scanning (for example gitleaks or your git host's scanning)
# to pre-commit hooks and CI so leaks are caught before merge.Rotate after any leak, even private repos
Deleting a commit does not remove a secret from clones, forks or caches; revoke and rotate it.
Quick check: What should you do first when a secret is committed to a repository?
- Only delete the file in the next commit
- Revoke and rotate the secret
- Make the repository private and do nothing else
- Rename the variable
Answer
Revoke and rotate the secret — Assume it has been copied.