Secrets management foundations
Before Vault, understand the problem: how secrets leak from env vars, logs, git history, CI, and container images; what Kubernetes secrets do and do not give you; how scanning, SOPS, sealed-secrets, and cloud managers keep GitOps honest; and what to do the hour a secret leaks.
01What counts as a secretCredentials, tokens, keys — and what is not one.20 min02How secrets leakLogs, ps, crash dumps, child processes, repos.25 min03Env vars, dotenv, and shellsWhy convenient delivery becomes permanent exposure.25 min04Secrets in git historyFinding, purging, and why you rotate anyway.25 min05CI logs, artifacts, and ticketsPipelines that print, upload, or paste secrets.25 min06Images, build args, and layersSecrets baked into layers you can still pull.25 min
01SOPS and sealed-secretsEncrypted values in git, for GitOps flows.30 min02Cloud secret managers, brieflyAWS/GCP/Azure managers without the deep dive.25 min03Rotation habits that stickDual-run windows and owners, not calendars alone.25 min04Choosing a secrets managerVault, cloud-native, or SOPS — a decision tree.20 min
Progress is saved in this browser only — no account required.
Final exam
Test yourself on everything
16 questions drawn from all 4 sections — every answer explained as you pick.