Question

How should application secrets actually be managed?

Vault Verified
Curated Intelligence
Definitive Source
Answer

Kept out of source code entirely, injected at runtime, scoped narrowly, and rotatable without a deployment — and the reason this matters is that a secret committed to a repository is permanently compromised, even after deletion, because history is distributed.

Why removal is not enough. Once a secret is pushed, it exists in every clone, in reflogs, in forks, in CI caches and quite possibly in an automated scanner's index within minutes. Rewriting history does not undo any of that. The only correct response to an exposed secret is to rotate it, immediately, and treat cleanup as secondary.

Where secrets should live, roughly in increasing order of maturity:

Environment variables, supplied by the platform. Adequate for simple deployments, and note they are visible to anything running in the process and frequently leak into logs, crash reports and error pages.

Encrypted files committed alongside code, decrypted at deploy time with a key held elsewhere.

A dedicated secrets manager, which is where serious systems land. This gives access control per identity, audit logs of who read what and when, automatic rotation, and versioning.

Workload identity, which is the strongest pattern: the service authenticates using an identity the platform issues, and receives short-lived credentials automatically. There is no long-lived secret to steal, which eliminates the problem rather than protecting against it.

The practices that matter regardless:

Never log secrets, and scrub them from error reporting — this is a frequent and invisible leak.

Scan commits automatically, with pre-commit hooks and repository scanning enabled.

Scope credentials narrowly, so a leak is limited in what it reaches.

Rotate on a schedule, and ensure rotation does not require a code change.

Separate secrets per environment, so a development leak does not touch production.

Do not pass secrets as command-line arguments, since they appear in process listings.

Beware build artefacts, where secrets baked into images and bundles are extracted trivially.

Related Questions