infra-secrets-management-review

Community

Harden secrets handling across your stack.

Authorivanshamaev
Version1.0.0
Installs0

System Documentation

What problem does it solve?

This Skill helps you eliminate insecure secret storage and access patterns across Vault, Kubernetes, Airflow, dbt, and CI/CD by turning ad-hoc practices into auditable, rotating, least-privilege workflows.

Core Features & Use Cases

  • Vault KV v2 & policy auditing: Review static (KV v2) secret layout, versioning, and access policies for specific workloads like Airflow connections and service accounts.
  • Dynamic credentials & lease renewal: Design short-lived database credentials and revocation flows using Vault dynamic database secrets.
  • External Secrets Operator (ESO) integration: Sync Vault-backed secrets into Kubernetes Secrets safely via scheduled refresh instead of embedding plaintext secrets in manifests.
  • Secret scanning and leak prevention: Set up pre-commit and CI secret scanning (gitleaks/truffleHog/Semgrep) to catch leaks in code and history.
  • Rotation and anti-pattern detection: Create a practical checklist that targets common failure modes like static passwords, plaintext logs, and missing audit logs.

Quick Start

Ask the agent: "Review our current secrets management and propose a migration plan to Vault (KV v2 + dynamic credentials) with ESO for Kubernetes and secret scanning in CI."

Dependency Matrix

Required Modules

None required

Components

Standard package

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: infra-secrets-management-review
Download link: https://github.com/ivanshamaev/de-agent-skills/archive/main.zip#infra-secrets-management-review

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.