Skip to slide
Chapter 12 · Secrets and Bring-Your-Own-Key
118 / 191

CHAPTER 12 · Secrets and Bring-Your-Own-Key · 10 / 10

The summary

  • Operator secrets live in the environment; user secrets live encrypted in the database.
  • Encrypt user secrets with AES-256-GCM: per-record IV, auth tag, key derived from an environment secret, fail closed on decryption.
  • Resolve credentials as user-beats-operator, with operator as fallback: one rule that serves both shared-key and BYOK deployments.
  • Expose status and source, never the secret.
  • Never log secrets; decrypt only at point of use.

Get this right and you can offer BYOK confidently, attribute costs correctly, and survive a database compromise without surrendering your users' credentials.

← → arrow keys work too