CHAPTER 12 · Secrets and Bring-Your-Own-Key · 10 / 10
The summary
- Operator secrets live in the environment; user secrets live encrypted in the database.
- Encrypt user secrets with AES-256-GCM: per-record IV, auth tag, key derived from an environment secret, fail closed on decryption.
- Resolve credentials as user-beats-operator, with operator as fallback: one rule that serves both shared-key and BYOK deployments.
- Expose status and source, never the secret.
- Never log secrets; decrypt only at point of use.
Get this right and you can offer BYOK confidently, attribute costs correctly, and survive a database compromise without surrendering your users' credentials.