DevSecOps: Secrets in the Cloud

DevSecOps: Secrets in the Cloud

May 21, 2018
By Derek Weeks

6 minute read time

System operators managing security often (maybe always) worry about secrets used to access their networks and resources that will get out or be setup incorrectly, exposing their systems.

If this describes someone you know, you can ease their worries with system hardening. Akash Mahajan ( @makash) told his personal journey with system hardening in his talk, The Secrets in Our Clouds. Perhaps his experiences could help you implement or improve system hardening for your own system.

Akash is with Appsecco, which is a relatively small company with typical production and staging requirements:

  1. They run multiple web applications with integrated authentication.
  2. They run multiple websites with authentication and authorization.
  3. In most cases, they terminate SSL/TLS at NGINX and reverse proxy to internal apps.
  4. They generate TLS certificates using Let's Encrypt.
  5. Whenever they add authentication as a middle-ware they rely on a SSO provider.
  6. Their apps need access to certain secrets, such as passwords and authentication tokens.

Akash said he started his system hardening journey with, "what I know best: installing and configuring software." He chose Vault and Goldfish because of its well-written installation instructions, and most of the complexity is hidden. Additionally, it seemed easy enough to expand.

Once your software is installed, you have to answer where to store the secrets and what secrets do we need to worry about. Examples of secrets include:

After this was setup for Akash, he still had nagging doubts and gnawing fears in the back of his mind:

What did Akash do? He switched hats from operations to security and didn't panic. He took a step back and thought of, "abstractions which are simple enough for me to understand." Some concepts that helped Akash include plaintext keys, secure storage, secure access, and the ability to choose which users see which secret.

Some attributes that helped Akash:

If you plan to store secrets in your cloud, Akash offered a few things to think about:

Akash wrapped up his talk with a recommendation to start simple, with two approaches for managing secrets: one for humans and another for systems.

For humans:

For systems:

If you are craving more on DevOps in Modern Infrastructure?
Binge watch any of the 20 DevOps in Modern Infrastructure sessions, free of charge, from All Day DevOps.

Written by Derek Weeks
Derek serves as vice president and DevOps advocate at Sonatype and is the co-founder of All Day DevOps, an online community of 65,000 IT professionals.