
5/15/2025
What this post added
This post details the evolution of Uber's Secrets Management Platform, focusing on the multi-cloud aspect and the implementation of automated secret rotation and deletion. Key contributions include: 1. Establishing a unified Secrets Management Standard and a visionary solution. 2. Deploying preventive (Git pre-commit hooks) and remediation (real-time and scheduled scanning of code, Slack, logs) strategies to combat secrets sprawl. 3. Consolidating 25 disparate secret vaults across multiple clouds into 6 centrally managed vaults, reducing blast radius and operational overhead. 4. Developing a core metadata model (secret provider, deployment platform, impact level) and building components for UI (API, CLI, web), lifecycle management, access control, third-party integrations, and an insights dashboard. 5. Enabling automated secret rotation and deletion by designing Secret Provider and Deployment Platform APIs, and integrating with various deployment platforms (Up, Kubernetes, Odin, Athena, YARN, Piper, DSW) to handle hundreds of secret types, including those requiring atomic pair rotation.