Live data from Hacker News

Ask HN: Tools for Managing Secret in Production Scale?

news.ycombinator.com

11–12 of 12 posts

Re: Ask HN: Tools for Managing Secret in Production Scale?

#11
My company uses AWS and started before Parameter Store and Secrets Manager and we try to not run our own infrastructure where possible because we are very small and don't have a big ops team.

We simply store our secrets in a KMS-encrypted file in S3. When containers start up, they have a bootstrap script that deserializes it and fills it with the appropriate variables.

At some point though I think we will look at Parameter Store and Secrets Manager. If I were starting this company again, that's where I'd look first.

Many will suggest Vault, which I hear is a fine product. However, it's one more thing that can fail, and this is a pretty big thing because if you can't access passwords and security tokens, most systems will totally stop working. If you are using a public cloud environment, I would look at tools native to that environment that are managed for you.

Re: Ask HN: Tools for Managing Secret in Production Scale?

#12
post #4

https://github.com/fugue/credstash https://aws.amazon.com/secrets-manager/

Thanks! How is your experience using that in production?

Unfortunately I haven't gotten a chance to use them in Prod. We used a homegrown process at my last company and we use Vault at my current company (which I haven't even used directly yet).

I mostly like credstash because I independently arrived at the same design for securing secrets before I knew it existed. And many of my security minded friends are excited to try out the AWS service.

Post reply on HN