|
|
|
Ask HN: Tools for Managing Secret in Production Scale?
|
|
12 points
by albertlie
2985 days ago
|
|
Hi all, I'm looking for centralized tools for managing secrets for my engineering team right now. Is there any recommended tools from your experience using them in production? For example like Vault (Hashicorp product). Thanks |
|
We simply store our secrets in a KMS-encrypted file in S3. When containers start up, they have a bootstrap script that deserializes it and fills it with the appropriate variables.
At some point though I think we will look at Parameter Store and Secrets Manager. If I were starting this company again, that's where I'd look first.
Many will suggest Vault, which I hear is a fine product. However, it's one more thing that can fail, and this is a pretty big thing because if you can't access passwords and security tokens, most systems will totally stop working. If you are using a public cloud environment, I would look at tools native to that environment that are managed for you.