← Engineering Dispatches / Security
Enterprise Secret Management & Zero-Leak CI/CD: HashiCorp Vault, Doppler & AWS Secrets
By Aman Aslam · 12 min read read
Architectural Takeaways
- Replace static, long-lived database credentials with dynamic, ephemeral roles generated on-demand by HashiCorp Vault that expire in 1 hour.
- Eliminate static cloud credentials in GitHub Actions using OpenID Connect (OIDC) identity federation with AWS IAM and Google Cloud.
- Enforce pre-commit hooks (TruffleHog, Gitleaks) to block secrets from ever entering git commit history.
1. The Dangers of Secret Sprawl in Modern Microservices
Static credentials rarely get rotated because developers fear breaking production. When a former employee leaves, static passwords remain compromised. Secret managers enforce automatic scheduled rotation.
2. Generating Dynamic Ephemeral Database Credentials
When an application pod needs database access, it authenticates with Vault, which generates a unique PostgreSQL user with a 1-hour lease. If the credential is ever leaked, it expires automatically.
3. Zero-Secret CI/CD with OpenID Connect (OIDC)
Using OIDC, GitHub Actions exchanges a cryptographic JWT signed by GitHub for temporary AWS STS credentials, eliminating static AWS_SECRET_ACCESS_KEY secrets from repository settings.
4. Automated Rotation & SOC 2 Access Auditing
Every secret access event is logged to immutable audit streams, providing the exact proof required for SOC 2 Type II and ISO 27001 certifications.
Read more technical guides on our Dispatches Index →