Knowledgebase

Securing Infrastructure Secrets Print

  • devopsinfrastructure, devops, security, hacked, woocommerce, troubleshooting, guide, howto
  • 0

Credentials at scale.

WHAT THE PROBLEM IS

Secrets needed by servers, pipelines and applications, in several places.

WHAT NOT TO DO

Copy them between places by hand Store them in a shared document Commit them anywhere

WHAT TO USE

Environment configuration per server A secrets manager, where the number justifies one

WHAT A SECRETS MANAGER PROVIDES

Central storage Controlled access An audit record Rotation

WHAT TO ROTATE

Anything exposed Anything held by someone who left Automation credentials, on a schedule

WHAT TO SCOPE

Each credential, to exactly what needs it.

WHY

So a compromise affects one thing rather than everything.

WHAT TO SEPARATE

Production credentials from every other environment.

WHY

Development environments are less protected, and frequently more widely accessible.

WHAT TO NEVER DO

Use production credentials in development Connect a development environment to production data

WHAT TO MONITOR

Use of sensitive credentials.

WHAT TO DOCUMENT

Where each is held, and who may access it.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot