CHAPTER 12 · Secrets and Bring-Your-Own-Key · 1 / 10
Two kinds of secrets
Distinguish:
- Operator secrets: credentials the operator configures for the whole deployment, held in environment variables / a secrets manager: the system's provider keys, database credentials, signing secrets. These never touch the database and never reach the client.
- User secrets: credentials individual users supply: their own provider API key, their own integration token. These must be stored (so they persist) but stored such that even someone with database access can't read them.
The architecture must handle both, and must define a clear precedence when both exist.