Dabish Digital
Cloud

Getting started with secrets management

There is no clever trick in this one, just a handful of decisions worth making deliberately. A short on-ramp to secrets management for teams who have not touched it before.

Cloud work rewards teams who automate early and punishes teams who click through consoles. If it only works because one person remembers to do something, it does not work yet.

The reason this keeps coming up

Secrets in a repository are a breach waiting for a schedule. Getting it slightly wrong is survivable. Ignoring it entirely is not. The teams that stay on top of it are the ones who put it on a calendar rather than a wish list.

Your first week

  1. Find out what is already in place
  2. Rotate them on a cadence, not after an incident
  3. Change one thing and measure it

Every secret should have a documented owner. The reasoning matters more than the rule, because the rule has exceptions. It rarely shows up as a line item, which is exactly why it slips.

How to tell if yours is fine

Operability is a feature, and it has to be built rather than bought. Three things worth confirming about secrets management before you move on:

  • Someone can say what the current setup is without going to look
  • Every secret should have a documented owner — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

Pick the one that would hurt most if it failed, and start there.