# Managing Secrets in CI — CI/CD Fundamentals: Pipelines, Testing and Deployment

Source: https://www.skillbyai.com/en/cicd/cicd-secrets-mgmt

> Keep credentials out of code with the CI secret store, narrow scopes and regular rotation.

## Never hardcode credentials

A password or API key committed to a repo is compromised the moment it's pushed — it lives in git history forever, even if you delete it later. Anyone with repo access (or a public repo, anyone at all) can read it.

## Encrypted secret stores

CI systems provide an encrypted secret store (GitHub Actions Secrets, GitLab CI Variables) or you integrate a vault (HashiCorp Vault, AWS Secrets Manager). Secrets are injected as environment variables only at run time, and hidden from logs.

## Scope and rotate

Give each secret the narrowest scope it needs (one environment, one job, read-only) and rotate credentials periodically so a leaked old key stops mattering.
