Skip to main content

Secrets

A managed vault for the credentials your workloads depend on — passwords, certificates, API keys, and encryption keys — so they never have to live in a configuration file or a repository.


Information​

Secrets is where sensitive material is stored and retrieved under access control rather than copied around. A secret belongs to a project, is retrieved by the identities entitled to that project, and can be revoked in one place.

Most credential exposure comes from secrets never being stored securely. Secrets provides an auditable, shared place for certificates, passwords, and keys, which services like load balancers can access directly instead of embedding them in configuration.

Out of the repository

Credentials are stored in the platform and fetched at run time, instead of being committed alongside the code that uses them.

Scoped to the project

A secret is owned by the project it was created in, so access follows the same boundary as every other resource.

Grouped into containers

Related secrets — a certificate, its private key, and a passphrase — are grouped in a container and referenced as one unit.

Consumed by the platform

Other services read from Barbican directly — most visibly the load balancer, which takes its TLS certificate from a Barbican container reference.


Usage​