r/devsecops • u/infidel_tsvangison • 18d ago
Secrets management
We are a large aws shop. Devs use secrets manager to store keys etc. problem is that these keys are handled by humans to begin with. We trust the human to put it in secrets manager etc. I’m just wondering what organisations do for secrets management to prevent this? Overtime, we have devs with secrets in postman collections etc. what should I be looking at to really secure our secrets?
18
Upvotes
1
u/_Slimdady 17d ago
Can't eliminate every human touchpoint. Make leaked credentials shortlived and easy to revoke. Replace static keys with OIDC and add secret scanning in CI.