Skip to slide
Chapter 12 · Secrets and Bring-Your-Own-Key
117 / 191

CHAPTER 12 · Secrets and Bring-Your-Own-Key · 9 / 10

Operational hygiene

  • Never log secrets. Scrub them from logs and error messages. Log "failed to decrypt key for provider X," not the key.
  • Least exposure. Decrypt a secret only at the moment of use, hold it briefly, don't pass it further than necessary.
  • Rotate the encryption secret carefully. Changing the key-derivation secret invalidates all stored user secrets; plan a re-encryption migration if you must rotate it.
  • Use a real secrets manager in production (rather than plain env files) where your platform offers one.
← → arrow keys work too