Secrets & KMS
Studies in this cluster, in series order. Each one keeps its own URL.
Security
AuthN, AuthZ, OAuth/OIDC, OWASP web attacks (injection, XSS, CSRF, SSRF, CORS), secrets/KMS, tokens, and service identity you can defend in interviews.
Secrets & KMS
6 studies- 1.Secrets & KMS — Envelope Encryption, Rotation & Blast RadiusCredentials, API keys, and data-encryption keys are high-blast-radius assets. This hub is the senior-SWE decision map for where secrets live, how KMS wraps data keys (envelope encryption), how you rotate without downtime, and how apps fetch secrets at runtime — without re-teaching OAuth/OIDC token flows or RBAC/ABAC policy engines. Focus: Vault, cloud Secrets Manager, and Kubernetes Secrets tradeoffs, the DEK/KEK/CMK hierarchy, dual-read rotation, injection paths, and leakage threat models.
- 2.Envelope Encryption — DEK, KEK & CMK HierarchyEnvelope encryption separates bulk data crypto (fast local AES with a DEK) from key protection (a KMS-held CMK or KEK wraps the DEK). This lesson is the DEK, KEK, and CMK hierarchy, the encrypt and decrypt paths, AAD, key policies, and rotation by re-wrap versus re-encrypt.
- 3.Secret Stores Compared — Vault, Cloud Secrets Manager & Kubernetes SecretsPicking a secret store is an architecture choice: dynamic leases in Vault, a managed cloud Secrets Manager, or Kubernetes-native Secrets plus CSI. This lesson compares trust boundaries, auth to the store, encryption at rest, HA, and anti-patterns — without rehashing OAuth grant types or full RBAC engines.
- 4.Credential Rotation — Dual-Read, Overlap Windows & Break-GlassRotation without downtime needs a dual-read overlap, version stages, and a rehearsed break-glass path. This lesson covers overlap windows, consumer lag, database password patterns, API key versioning, and what fails when only half the fleet has the new secret.
- 5.App Secret Injection — Env, Sidecar/Agent, CSI Drivers & Runtime FetchHow an app obtains a secret matters as much as where it is stored. This lesson compares environment variables, file mounts, Vault Agent and cloud sidecars, the Secrets Store CSI driver, and runtime SDK fetch — with blast radius and operational tradeoffs for Kubernetes and VMs.
- 6.Secrets Threat Model — Leakage Paths, Side Channels & Audit TrailsEven perfect KMS math fails if secrets leak through logs, CI, cores, tickets, or over-broad IAM. This lesson catalogs leakage paths, side channels, detection via audit trails, and incident response for credential exposure — closing the Secrets and KMS cluster.