Passwords and secrets in infrastructure code

Secrets in code can leak through repository history and deployment artifacts.

Description

Passwords, API keys, tokens, or private keys written directly in infrastructure code can expose credentials to people with access to the repository or deployment artifacts. Deleting a value from a file can leave it in commit history and other copies.

Potential impact

An exposed credential can grant access to services or data within the account’s permissions.

Remediation

Store secrets in a secret management service and reference or inject them during deployment. Revoke and replace exposed credentials, then remove them from code and historical copies. Kubernetes Secrets also need access restrictions and encryption at rest.

Examples

The revised example only shows passing a value from the separately created secret-basic-auth Secret into an environment variable. Application configuration that consumes the value is omitted.

Before

yaml
apiVersion: v1
kind: Secret
metadata:
  name: secret-basic-auth
type: kubernetes.io/basic-auth
stringData:
  password: "root"

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: nginx
spec:
  containers:
    - name: nginx
      image: nginx
      env:
        - name: PASSWORD
          valueFrom:
            secretKeyRef:
              name: secret-basic-auth
              key: password

References