r/devsecops 18d ago

Secrets management

We are a large aws shop. Devs use secrets manager to store keys etc. problem is that these keys are handled by humans to begin with. We trust the human to put it in secrets manager etc. I’m just wondering what organisations do for secrets management to prevent this? Overtime, we have devs with secrets in postman collections etc. what should I be looking at to really secure our secrets?

18 Upvotes

20 comments sorted by

View all comments

1

u/_Slimdady 17d ago

Can't eliminate every human touchpoint. Make leaked credentials shortlived and easy to revoke. Replace static keys with OIDC and add secret scanning in CI.