Secrets Management Overview
Master enterprise secrets management, centralizing, rotating, and securely injecting credentials using HashiCorp Vault, Cloud Secrets Managers, and Kubernetes hardening patterns.
01. Introduction & Threats
Explore the theoretical foundations of secrets management, the anatomy of secret sprawl, real-world breach case studies, and the formal 6-stage secrets lifecycle.
02. HashiCorp Vault Deep Dive
Master HashiCorp Vault architecture, AppRole & Kubernetes authentication, KV v2 versioning, dynamic database credentials, transit envelope encryption, and multi-language SDK integrations.
03. Cloud Secrets Managers
Compare AWS Secrets Manager, GCP Secret Manager, and Azure Key Vault. Implement identity-based access control, local caching, and SDK code in Python, Node.js, Go, and Java.
04. Kubernetes Secrets Hardening
Harden Kubernetes secrets by configuring etcd KMS encryption at rest, deploying External Secrets Operator, using Secrets Store CSI Driver with tmpfs, and managing GitOps secrets with Sealed Secrets and SOPS.
05. Scanning & Rotation
Implement pre-commit hooks, Gitleaks, and TruffleHog in CI/CD pipelines, execute git history purges, and build automated 4-state secret rotation workflows.
06. Hands-On Lab
A self-contained runnable lab. Exploit a microservice with hardcoded secrets and environment variable leaks, then remediate it using HashiCorp Vault AppRole authentication and dynamic DB credentials.
07. References & Standards
Authoritative references, NIST SP 800-57 guidelines, PCI DSS v4.0 requirements, CIS Kubernetes benchmarks, CWE taxonomy, and open-source tooling catalog.