Lesson 4.219mIntermediate6.4k students

Secrets management

Secrets belong in a manager, injected at runtime, never in the repository. Assume anything committed once is compromised forever.

This lesson sits in Hardening and Supply Chain, part of Practical Web Security. It assumes what came before it and leads directly into the next lesson in the module.

In this lesson you will

  • Keep credentials out of source control
  • Inject secrets at runtime and scope them tightly
  • Rotate credentials and revoke exposed ones immediately

Pro tip

A secret committed once is compromised even after you delete the commit. Rotate it, do not just remove it.

Resources