Menu

Post image 1
Post image 2
1 / 2
0

Gitlfow Secrets Management

DEV Community·Neil·21 days ago
#jM3XubtD
Reading 0:00
15s threshold

Opening Someone had rotated the API keys manually — without telling anyone. The rotation got lost in Slack three days ago. Now we had 47 repositories with stale credentials, half our integration tests dead, and no way to fix them in bulk. Everythign is failing no code changes what is going on ? That was the moment I realized our "secrets management" was actually just secrets chaos. The Real Problem Nobody Talks About Most engineering teams don't have a secrets management problem. They have a visibility problem. Here's what actually happens: Credentials rotate and half your teams don't know New repos get created and old secrets get copy-pasted into them (because it's faster than figuring out the "right way") Validation is manual — you hope each repo has the secrets it needs Compliance audits come and you scramble for a log of who accessed what Someone leaves and you have a 2-week hunt for every system their credentials are in Rotation policies exist but nobody knows if they're actually running S3 leaks,…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More