SSCP Systems Security Certified PractitionerSystems and Application SecurityMedium
A software development team is implementing a new microservices architecture. They need a mechanism to securely manage and distribute secrets, such as API keys and database credentials, to different services without hardcoding them into the application code or configuration files. Which of the following solutions would best address this requirement?
- AEmbedding secrets directly into the service's Docker images.
- BEncrypting secrets and storing them in a shared network drive.
- CStoring secrets in environment variables on each server.
- DUsing a dedicated secrets management solution.
Show answer & explanationAnswer & explanation
Correct answer: D. Using a dedicated secrets management solution.
A dedicated secrets management solution provides a secure, centralized way to store, access, and audit secrets, offering features like encryption at rest, access control, and rotation, which is crucial for microservices.
Why the other options are wrong
- A. Embedding secrets into Docker images is highly insecure as images can be inspected, and secrets become static and difficult to rotate.
- B. Storing encrypted secrets on a shared network drive introduces risks from the drive's access controls and still requires a secure way to distribute decryption keys.
- C. Environment variables are better than hardcoding but can still be exposed through process introspection or logs and lack centralized management and rotation.
Secrets Management
The tools and methods used to manage digital authentication credentials (secrets) for applications, services, and users, ensuring they are stored, distributed, and accessed securely.
- Prevents hardcoding of sensitive information.
- Enables centralized control, auditability, and rotation of secrets.
- Essential for modern distributed architectures like microservices.
Memory trick: Secret keys need a vault, not just a lock and key.