Keel

Fundamentals2 min read

What is secrets management? A practical guide for developers

Secrets management is how you store, distribute, and control access to credentials such as API keys and database passwords. Here is what it covers and where to start.

By the Keel team

Secrets management is the practice of storing sensitive credentials in a controlled system, delivering them to the software and people that need them, and keeping a record of who accessed what. A secret is any value that grants access: an API key, a database password, a signing key, an OAuth client secret, a webhook token.

What counts as a secret

The test is simple: if someone who obtained the value could do something they should not be able to do, it is a secret. A database URL with an embedded password is a secret. The port number of your dev server is not. Many configuration values sit in between, which is why environment variables and secrets are not the same thing.

The problems it solves

  • Sprawl: the same key lives in a .env file, a CI setting, a chat message, and a wiki page, and nobody knows which is current.
  • Leakage: values end up in Git history, container images, logs, and screenshots.
  • Over-access: everyone on the team can read production credentials because there is no other way to share them.
  • No trail: when a key is abused, there is no record of who had it.
  • Painful change: replacing a credential means hunting down every copy.

What a secrets manager does

  1. Encrypts values at rest, so a database dump alone is not enough to read them.
  2. Controls access by role and environment, so a contractor can read development values without seeing production.
  3. Delivers values to applications at runtime or deploy time, rather than baking them into code or images.
  4. Records reads, changes, and denied attempts in an audit log.
  5. Keeps history, so a bad change can be undone.

A realistic starting point

You do not need a large platform on day one. Begin with three habits: keep secrets out of source control, give each environment its own values, and store the real values somewhere with access control and an audit trail instead of a shared file. The OWASP Secrets Management Cheat Sheet is a good reference for going further.

What secrets management does not do

It does not make a leaked secret safe, and it does not fix an application that logs its own credentials. It reduces how many places a secret lives and how many people can reach it. You still need to rotate credentials that were exposed, and to scope each key to the least privilege it needs.

If you want to see how this looks in a product, read about how Keel handles secrets management.