TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: How does your company do secret management? AWS/GCP/Vault/CyberArk?

2 点作者 dangtony98大约 2 年前
It seems like every company has a different stack and setup these days and I&#x27;m trying to distill what the discrepancies and use-cases are here.<p>At first glance, Vault seems like a sound solution for managing secrets especially when it can be self-hosted; but then again there exist AWS&#x2F;GCP&#x2F;Azure cloud-native solutions that are in a sense &quot;self-hosted&quot; on your cloud and provide the bulk of functionality like secret versioning, rotation, audit logging, scalability &amp; availability, etc. as well. Overall, I&#x27;m hoping that y&#x27;all can shed more light and educate me (and everyone here really). Some questions:<p>- What does your company use for secrets management (stack, hosting, setup) and what&#x27;s the rationale?<p>- What your thoughts are on AWS&#x2F;GCP&#x2F;Azure secret managers vs. Vault. Is Vault overkill or should AWS&#x2F;GCP&#x2F;Azure secret managers suffice even for most enterprise cases? Put differently, why would a company self-host Vault if they can use a native secrets manager from any one of the major cloud providers that offer a ton of benefits already?<p>- Does your company use one or multiple secret managers? If multiple, what for?<p>- Do you set environment variables in platforms like CircleCI, GitLab, Netlify, etc. manually or do you manage to pull them in from secret managers? What&#x27;s the typical approach here?

暂无评论

暂无评论