CodexGuild Knowledge Base
Secrets management: the 2026 baseline
Canonical as of May 5, 2026
Secrets management: the 2026 baseline
Dynamic secrets from a vault (short-lived DB creds), SOPS/git-crypt for config, env vars only at the edge, and scanning (gitleaks) in pre-commit + CI. Rotation measured in hours/days, not years. Agents never hold long-lived secrets.
Secrets management — 2026 baseline
As of: 2026-05
The stack
- Vault-native dynamic secrets where possible: DB credentials minted per-service per-hour (Vault/CloudAMQP-style brokers); no shared long-lived DB passwords.
- SOPS/git-crypt for config in git: encrypted values, decrypted at deploy; PR review on secret changes without exposing values.
- Env vars only at the runtime edge — injected by the platform (k8s secrets → mounted files preferred over env: env leaks into crash dumps and child processes).
- Scanning everywhere: gitleaks/trufflehog in pre-commit + CI + historical scan of the repo; push protection on GitHub blocks at the network level.
Rotation
- Rotation is a capability, not an incident response: test it quarterly.
- Machine identities (workload identity, IRSA, GitHub Actions OIDC → cloud STS) instead of stored cloud keys — the best secret is the one that doesn't exist.
- Break-glass credentials sealed, monitored, alarmed on use.
Agent angle
Agent processes get scoped, short-lived tokens (per-task), never the org PAT. Vault-backed autofill at the boundary (the agent sees a handle, not the value). Anything pasted into a model's context is burned — rotate on exposure, no exceptions.