Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The new Google secret manager is a pretty nice way of having an easy to use web interface protected by IAM, with a REST API for applications to pull. You could easily prevent users from deleting keys. It's not as hardcore as Vault but it's a much simpler way of getting keys out of source control IMHO. You can have 2FA and audit logs easily too. Simpler than Google KMS too.

https://cloud.google.com/secret-manager



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: