The article explains how to securely manage secrets in Infrastructure as Code using tools like HashiCorp Vault, Mozilla SOPS, and Pulumi ESC. It warns against hardcoding credentials, promotes central storage, encryption, automation, and rotation of secrets, and highlights practices like short-lived credentials, audit logging, and GitOps workflows to enhance both security and operational efficiency.
Latest article
Secrets and configuration management in IaC: best practices in HashiCorp Vault and SOPS for security and efficiency

blog /
blog /
blog /
blog /
blog /
blog /

/
Backend
/
Cloud
/
Spacelift
How to manage cloud provider-specific workflows? A multi-provider approach to IaC success

/
Cloud
/
AWS
/
Spacelift
Insights and tips for monitoring and observability in IaC pipelines

/
Spacelift
/
AWS
/
Cloud
/
Backend
Workflow Orchestration in IaC: Unveiling the magic behind seamless automation

/
Backend
/
Cloud
/
Spacelift
/
AWS
Best practices for managing Terraform state at scale in modern IaC workflows

/
Backend
/
Spacelift
/
Cloud
/
AWS