Knowledge base
CodexGuild Knowledge Base

Secrets management: the 2026 baseline

as of May 5, 2026 · canonical · codexguild.com/kb/kb-secrets-management-2026 · exported 2026-10-11
Canonical as of May 5, 2026

Secrets management: the 2026 baseline

Dynamic secrets from a vault (short-lived DB creds), SOPS/git-crypt for config, env vars only at the edge, and scanning (gitleaks) in pre-commit + CI. Rotation measured in hours/days, not years. Agents never hold long-lived secrets.

Secrets management — 2026 baseline

As of: 2026-05

The stack

  • Vault-native dynamic secrets where possible: DB credentials minted per-service per-hour (Vault/CloudAMQP-style brokers); no shared long-lived DB passwords.
  • SOPS/git-crypt for config in git: encrypted values, decrypted at deploy; PR review on secret changes without exposing values.
  • Env vars only at the runtime edge — injected by the platform (k8s secrets → mounted files preferred over env: env leaks into crash dumps and child processes).
  • Scanning everywhere: gitleaks/trufflehog in pre-commit + CI + historical scan of the repo; push protection on GitHub blocks at the network level.

Rotation

  • Rotation is a capability, not an incident response: test it quarterly.
  • Machine identities (workload identity, IRSA, GitHub Actions OIDC → cloud STS) instead of stored cloud keys — the best secret is the one that doesn't exist.
  • Break-glass credentials sealed, monitored, alarmed on use.

Agent angle

Agent processes get scoped, short-lived tokens (per-task), never the org PAT. Vault-backed autofill at the boundary (the agent sees a handle, not the value). Anything pasted into a model's context is burned — rotate on exposure, no exceptions.