role-devops:secrets-management
Secrets management expertise covering HashiCorp Vault, AWS Secrets Manager, GCP Secret Manager, SOPS, Kubernetes sealed secrets, rotation policies, zero-trust injection, environment variable management, and CI/CD secrets handling.
SKILL.md
Full skill instructions
Secrets Management
When to use
- Setting up or auditing a centralized secret store (Vault, cloud-native, or SOPS)
- Configuring runtime secret injection into Kubernetes pods or containers
- Designing secret rotation schedules and automation
- Hardening CI/CD pipelines to eliminate long-lived credentials
- Reviewing whether secrets are leaking via env vars, logs, or image layers
- Implementing OIDC federation to replace static cloud credentials in pipelines
Core principles
- Never at build time — secrets injected at runtime, never baked into images or configs
- Files over env vars — file-based injection doesn't leak via process listings or error reports
- Rotate everything automatically — manual rotation processes become forgotten security debt
- Least privilege per service — each workload gets only the secrets it needs, nothing more
- Audit every access — every read from a secret store must be logged for forensic use
Reference Files
references/vault-cloud-sops.md— Core principles, HashiCorp Vault HA/auto-unseal/KV v2/dynamic secrets/Kubernetes auth/audit backend, AWS Secrets Manager and GCP Secret Manager resource policies and rotation, SOPS encryption with KMS/PGP and Helm secrets plugin, Bitnami Sealed Secrets with kubeseal and key rotation schedule, rotation policy schedules by secret type (DB/API/TLS/SSH/tokens)references/injection-cicd.md— Zero-trust runtime injection patterns, Vault Agent Injector annotations, CSI Secret Store Driver SecretProviderClass, file-based injection preference rationale, startup env var validation pattern, GitHub Secrets and GitLab CI Variables scoping, OIDC federation for AWS and GCP from GitHub Actions/GitLab CI, CI log masking verification
Best Practices Checklist
- No secrets in source code, Dockerfiles, or CI configs
- Centralized secret store (Vault, cloud-native, or SOPS)
- Automated rotation with defined schedules
- Least-privilege access policies per service
- Audit logging enabled for all secret access
- Runtime injection, not build-time baking
- OIDC federation for CI/CD cloud authentication
.envfiles excluded from version control
