π¦ ClawHub
env-secrets-manager
by @alirezarezvani
Env & Secrets Manager
β‘ When to Use
π Tips & Best Practices
1. Secret manager is source of truth β .env files are for local dev only; never in prod 2. Rotate on a schedule, not just after incidents β quarterly minimum for long-lived keys 3. Principle of least privilege β each service gets its own API key with minimal permissions 4. Audit access β log every secret read in Vault/SSM; alert on anomalous access 5. Never log secrets β add log scrubbing middleware that redacts known secret patterns 6. Use short-lived credentials β prefer OIDC/instance roles over long-lived access keys 7. Separate secrets per environment β never share a key between dev and prod 8. Document rotation runbooks β before an incident, not during one
TERMINAL
clawhub install env-secrets-manager