Secret Management
DevOps pipelines handle sensitive data like API keys, database credentials, and private keys. Hardcoding these secrets in configuration files or version control systems exposes them to unauthorized access, compliance violations, and potential breaches. Secure secret management tools like HashiCorp Vault, AWS Secrets Manager, and Azure Key Vault provide encrypted storage, access control, and automated rotation, ensuring secrets are protected throughout the CI/CD lifecycle. This section guides you through integrating these tools into pipelines and adopting best practices to minimize risk.
Choosing a Secret Management Tool¶
Select a tool based on your infrastructure, team expertise, and compliance requirements. Popular options include:
- HashiCorp Vault: Offers dynamic secrets, encryption-as-a-service, and fine-grained access policies.
- AWS Secrets Manager: Integrates seamlessly with AWS services and provides automatic secret rotation.
- Azure Key Vault: Ideal for Azure environments, with built-in encryption and access controls.
Each tool requires configuration to store, retrieve, and rotate secrets securely. For example:
# HashiCorp Vault: Store a secret
vault kv put secret/myapp/db-password value="s3cr3t"
# AWS Secrets Manager: Create a secret
aws secretsmanager create-secret --name myapp-db-password --secret-string '{"username": "admin", "password": "s3cr3t"}'
Integrating with CI/CD Pipelines¶
Integrate secret management tools into pipelines to fetch secrets dynamically during builds and deployments. Use environment variables, API calls, or tool-specific plugins to avoid exposing credentials in code.
Example: GitHub Actions with AWS Secrets Manager¶
# .github/workflows/build.yml
name: Build App
on: [push]
jobs:
build:
runs-on: ubuntu-latest
steps:
- name: Get secret
id: get-secret
uses: aws-actions/secretsmanager-get-secret-value@v1
with:
secret-id: myapp-db-password
region: us-west-2
- name: Use secret
run: |
echo "Database password: ${{ steps.get-secret.outputs.secret }}"
Example: Jenkins with HashiCorp Vault¶
// Jenkins pipeline script
stage('Retrieve Secret') {
steps {
script {
def secret = sh(script: 'vault kv get secret/myapp/db-password', returnStdout: true).trim()
echo "Secret: $secret"
}
}
}
Best Practices for Secure Secret Management¶
- Rotate Secrets Regularly: Automate rotation using tools like Vault’s lease management or AWS Secrets Manager’s built-in rotation.
- Limit Access: Use IAM roles, policies, or Vault ACLs to restrict access to secrets. For example, grant read-only access to specific services.
- Encrypt at Rest: Ensure secrets are encrypted when stored, using tools’ native encryption or external KMS services.
- Avoid Hardcoding: Never embed secrets in code or config files. Use environment variables or secret managers instead.
- Audit and Monitor: Enable logging and alerts for secret access attempts, and regularly scan for exposed secrets in repositories.
Key takeaways¶
- Use trusted secret management tools (e.g., Vault, AWS Secrets Manager) to store, retrieve, and rotate secrets securely.
- Integrate these tools into CI/CD pipelines to fetch secrets dynamically, avoiding hardcoded credentials.
- Follow best practices like access control, encryption, and regular rotation to minimize exposure.
- Combine secret management with secrets scanning tools to detect and remediate exposed credentials in code.
- Prioritize least-privilege access and audit trails to ensure compliance and reduce attack surfaces.