Secrets management in practice: secret stores, rotation, CI/CD secrets and scanning
For developers, DevOps engineers and systems administrators who already know not to commit keys and now need to run secrets properly: where each secret should live, who can read it, how it's rotated, how pipelines use it without leaking it, and how leaks are detected and handled. It builds on Git fundamentals and Secure development basics (OWASP Top 10). Uses the OWASP Secrets Management Cheat Sheet as the backbone, with GitHub, HashiCorp Vault, AWS Secrets Manager and Azure Key Vault documentation as worked examples; the ideas carry over to other tools. Your organisation's secrets standard and incident process decide which tools you use and who approves access. Ends with a supervisor-graded review of a lab repository and pipeline.
- Level
- Intermediate
- Length
- About 100 minutes
- Contents
- 5 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Choose where a secret should live (secret store, CI/CD secret or short-lived workload identity) and who can read it, using least privilege and separation by environment
- Plan rotation for a static secret, choosing a single-user or alternating-users strategy, and identify where dynamic secrets with leases fit better
- Identify CI/CD pipeline configurations that expose secrets and correct them
- Choose secret-scanning and push-protection controls and triage a detection by validity and exposure
- Write a secret-exposure response record covering revocation, rotation, deletion and a review of access and use
Course outline
- 1.Choose where a secret lives and who can read itLesson · 20 min
- 2.Plan rotation for static secrets and use dynamic secrets where they fitLesson · 20 min
- 3.Identify and correct CI/CD configurations that expose secretsLesson · 20 min
- 4.Choose secret-scanning controls and triage a detectionLesson · 16 min
- 5.Write a secret-exposure response recordLesson · 12 min
- 6.Secrets management in practice: secret stores, rotation, CI/CD secrets and scanning: knowledge checkKnowledge check · 14 questions
- 7.Secrets management in practice: secret stores, rotation, CI/CD secrets and scanning: practical exerciseKnowledge check · 1 question
- 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- OWASP Cheat Sheet Series: Secrets Management Cheat Sheet
- GitHub Docs: Secret scanning
- GitHub Docs: Push protection
- GitHub Docs: Using secrets in GitHub Actions
- GitHub Docs: Secure use reference (GitHub Actions, using secrets)
- GitHub Docs: OpenID Connect (GitHub Actions)
- HashiCorp Vault documentation: Lease, renew and revoke
- AWS Secrets Manager User Guide: Rotate AWS Secrets Manager secrets
- AWS Secrets Manager User Guide: Lambda function rotation strategies (single user, alternating users)
- Microsoft Learn: Secure your Azure Key Vault (best practices)
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.