Credentials at scale.
WHAT THE PROBLEM IS
Secrets needed by servers, pipelines and applications, in several places.
WHAT NOT TO DO
Copy them between places by hand Store them in a shared document Commit them anywhere
WHAT TO USE
Environment configuration per server A secrets manager, where the number justifies one
WHAT A SECRETS MANAGER PROVIDES
Central storage Controlled access An audit record Rotation
WHAT TO ROTATE
Anything exposed Anything held by someone who left Automation credentials, on a schedule
WHAT TO SCOPE
Each credential, to exactly what needs it.
WHY
So a compromise affects one thing rather than everything.
WHAT TO SEPARATE
Production credentials from every other environment.
WHY
Development environments are less protected, and frequently more widely accessible.
WHAT TO NEVER DO
Use production credentials in development Connect a development environment to production data
WHAT TO MONITOR
Use of sensitive credentials.
WHAT TO DOCUMENT
Where each is held, and who may access it.