Module 12 of 13

Secret Management

Lessons

About This Module

Every module so far has quietly relied on one thing working correctly: keeping passwords, API keys, and certificates out of the wrong hands. This module covers secret management properly — why it matters, why environment variables aren't enough on their own, and how a dedicated secret store like HashiCorp Vault centralizes and controls access to sensitive data.

It also covers cloud-native secret managers like AWS Secrets Manager, Azure Key Vault, and GCP Secret Manager, the specifics and limitations of Kubernetes Secrets, rotating and expiring secrets automatically, encryption at rest and in transit, and auditing access so you know exactly who touched what.

Watch the lessons in order, then continue on to Observability.

Lessons

8 videos
01

Why Secret Management Matters

The real-world cost of leaked credentials, and why "just don't commit it to Git" isn't a strategy on its own.

02

Environment Variables vs Dedicated Secret Stores

Where plain environment variables fall short — visibility, rotation, auditing — and what a purpose-built secret store adds.

03

HashiCorp Vault Basics

Storing, retrieving, and dynamically generating secrets with Vault, and how its access policies control who can read what.

04

Cloud-Native Secret Managers

Using AWS Secrets Manager, Azure Key Vault, and GCP Secret Manager to store secrets natively within each cloud platform.

05

Kubernetes Secrets & Their Limitations

How Kubernetes Secrets work under the hood, why they're only base64-encoded by default, and when to pair them with an external secret store.

06

Secret Rotation & Expiration

Automatically rotating credentials on a schedule so a leaked secret has a short shelf life instead of living forever.

07

Encryption at Rest & in Transit

How secrets stay protected both while stored and while moving across the network, and where TLS fits into that picture.

08

Auditing & Least-Privilege Access to Secrets

Logging every access to a secret, and scoping permissions so each service or person can only reach what they actually need.