Secrets management — Vault & encryption — POC
The problem. Secrets lie around everywhere: .env files, CI variables, Git repos. One leak and everything falls.
What I prototype
- HashiCorp Vault: central storage, controlled access (policies), audit.
- Dynamic rotation of secrets and time-limited leases.
- SOPS + age/GPG to encrypt secrets versioned in Git (GitOps-friendly).
- Zero plaintext secrets: runtime injection, least privilege.
Stack
Vault · SOPS · age/GPG · Kubernetes · CI/CD
POC — security test bed, not deployed to production.