How do I store secrets in CI/CD?
Built-in Secret Stores
Most CI/CD tools provide a way to store secrets securely. For example, GitHub Actions has encrypted secrets, GitLab CI has masked variables, and Jenkins has credentials plugins. These secrets are injected into the pipeline as environment variables or files, and they are not exposed in logs.
You can scope secrets to specific environments (e.g., production vs. staging) and restrict which branches or users can access them. This limits the blast radius if a secret is compromised.
External Secret Managers
For stronger security and central management, integrate an external secret manager like HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, or Google Secret Manager. Your pipeline authenticates to the manager and fetches secrets at runtime.
This approach keeps secrets out of the CI system entirely and provides audit logs, rotation, and fine-grained access control. It adds complexity, so it's often used by larger teams or those with compliance requirements.
- Never commit secrets to version control
- Use environment variables for injection
- Rotate secrets regularly
- Limit secret access to necessary pipelines
- Audit secret usage
Common mistakes
- Storing secrets in plain text in CI configuration files or code repositories.
- Printing secrets in logs by echoing them or enabling debug output.
- Using the same secret across multiple environments, increasing risk if leaked.
