How do I store secrets in CI/CD?

Updated October 2026 · How we answer

Short answerUse your CI/CD platform's built-in secret management (like GitHub Secrets, GitLab CI variables, or Jenkins credentials) to store sensitive values encrypted. Never hardcode secrets in code or config files; inject them as environment variables at runtime.

Built-in Secret Stores

Most CI/CD tools provide a way to store secrets securely. For example, GitHub Actions has encrypted secrets, GitLab CI has masked variables, and Jenkins has credentials plugins. These secrets are injected into the pipeline as environment variables or files, and they are not exposed in logs.

You can scope secrets to specific environments (e.g., production vs. staging) and restrict which branches or users can access them. This limits the blast radius if a secret is compromised.

External Secret Managers

For stronger security and central management, integrate an external secret manager like HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, or Google Secret Manager. Your pipeline authenticates to the manager and fetches secrets at runtime.

This approach keeps secrets out of the CI system entirely and provides audit logs, rotation, and fine-grained access control. It adds complexity, so it's often used by larger teams or those with compliance requirements.

  • Never commit secrets to version control
  • Use environment variables for injection
  • Rotate secrets regularly
  • Limit secret access to necessary pipelines
  • Audit secret usage

Common mistakes

  • Storing secrets in plain text in CI configuration files or code repositories.
  • Printing secrets in logs by echoing them or enabling debug output.
  • Using the same secret across multiple environments, increasing risk if leaked.
From our shopsTitan Case: Premium MagSafe iPhone cases with a precision fit.