Lesson 18 / 21

Managing Secrets in CI

Credentials must never live in code — they live in the CI system's vault.

Never hardcode credentials

A password or API key committed to a repo is compromised the moment it's pushed — it lives in git history forever, even if you delete it later. Anyone with repo access (or a public repo, anyone at all) can read it.

Encrypted secret stores

CI systems provide an encrypted secret store (GitHub Actions Secrets, GitLab CI Variables) or you integrate a vault (HashiCorp Vault, AWS Secrets Manager). Secrets are injected as environment variables only at run time, and hidden from logs.

Scope and rotate

Give each secret the narrowest scope it needs (one environment, one job, read-only) and rotate credentials periodically so a leaked old key stops mattering.