{"id":5255,"date":"2026-10-08T13:35:38","date_gmt":"2026-10-08T13:35:38","guid":{"rendered":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/10\/08\/secrets-sprawl-and-rotation-a-practical-vault-management-playbook\/"},"modified":"2026-10-08T13:35:38","modified_gmt":"2026-10-08T13:35:38","slug":"secrets-sprawl-and-rotation-a-practical-vault-management-playbook","status":"publish","type":"post","link":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/10\/08\/secrets-sprawl-and-rotation-a-practical-vault-management-playbook\/","title":{"rendered":"Secrets Sprawl and Rotation: A Practical Vault Management Playbook"},"content":{"rendered":"<div><img data-opt-id=1338428838  fetchpriority=\"high\" decoding=\"async\" width=\"770\" height=\"330\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/10\/secrets_sprawl_ai_770x330.jpg\" class=\"attachment-large size-large wp-post-image\" alt=\"\" \/><\/div>\n<p><img data-opt-id=941898541  fetchpriority=\"high\" decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/10\/secrets_sprawl_ai_770x330-150x150.jpg\" class=\"attachment-thumbnail size-thumbnail wp-post-image\" alt=\"\" \/><\/p>\n<p><span>In 2025 alone, <\/span><a href=\"https:\/\/www.gitguardian.com\/state-of-secrets-sprawl-report-2026\" target=\"_blank\" rel=\"noopener\"><span>security firm GitGuardian<\/span><\/a><span> detected <\/span><a href=\"https:\/\/blog.gitguardian.com\/the-state-of-secrets-sprawl-2026\/#:~:text=Secrets%20Sprawl%22%20report%2C-,28.65,-million%20new%20hardcoded\" target=\"_blank\" rel=\"noopener\"><span>28.65 million new hardcoded secrets<\/span><\/a><span> exposed in public GitHub commits \u2014 a 34% increase year over year and the largest single-year jump the company has recorded in five years of publishing its annual <\/span><a href=\"https:\/\/blog.gitguardian.com\/the-state-of-secrets-sprawl-2026\/\" target=\"_blank\" rel=\"noopener\"><span>State of Secrets Sprawl<\/span><\/a><span> report. Since 2021, that number has grown 152%, far outpacing the 98% growth in GitHub\u2019s active developer base over the same period. Secrets sprawl isn\u2019t a hypothetical DevOps hygiene problem anymore. It\u2019s accelerating faster than most security teams can respond to it, and AI-assisted development is a large part of why.<\/span><\/p>\n<p><span>The financial stakes keep climbing alongside it. IBM\u2019s newly released 2026 <\/span><a href=\"https:\/\/www.ibm.com\/reports\/data-breach\" target=\"_blank\" rel=\"noopener\"><span>Cost of a Data Breach Report<\/span><\/a><span> puts the global average cost of a breach at $4.99 million, a 12% increase over the prior year and a new record high. In <\/span><a href=\"https:\/\/spycloud.com\/blog\/6-takeaways-from-ibm-data-breach-report-2025\/\" target=\"_blank\" rel=\"noopener\"><span>IBM\u2019s 2025 edition<\/span><\/a><span>, breaches where compromised credentials were the initial access vector carried a $4.67 million average cost on their own, and organizations took an average of 246 days just to identify and contain them. A single hardcoded credential, sitting in a repository or a config file for months, is exactly the kind of quiet, slow-burning exposure that produces numbers like these.<\/span><\/p>\n<h3><span>Why Secrets Sprawl is Getting Worse, Not Better<\/span><\/h3>\n<p><span>The intuitive assumption is that better tooling and more awareness should be shrinking this problem over time. The data says the opposite is happening, and AI-assisted coding is a specific, identifiable accelerant.<\/span><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/03\/the-state-of-secrets-sprawl-2026-9.html\" target=\"_blank\" rel=\"noopener\"><span>GitGuardian\u2019s 2026 report<\/span><\/a><span> found that secrets tied to AI services grew 81.5% year over year, making them the fastest-growing category of leaked credentials in the entire dataset. Model context protocol (MCP) configuration files, which became a de facto standard for connecting LLMs to external tools and data sources in 2025, already had 24,008 unique secrets exposed in their first year of widespread use. The report links this pattern partly to official documentation that suggests passing API keys as command-line arguments or storing them directly in JSON config files. The report also found that commits produced with AI coding assistance leaked secrets at roughly twice the rate of the GitHub-wide baseline. This was not because AI tools are malicious, but because they generate working code quickly, including secrets, without the natural pause a developer might take to ask whether a credential belongs in that file.<\/span><\/p>\n<p><span>The consequences of this pattern aren\u2019t abstract. GitGuardian\u2019s research points to the <\/span><a href=\"https:\/\/nhimg.org\/the-state-of-secrets-sprawl-2026\" target=\"_blank\" rel=\"noopener\"><span>Smithery.ai incident<\/span><\/a><span> as a concrete illustration: A path-traversal vulnerability in an MCP registry exposed overprivileged tokens, granting arbitrary code execution across more than 3,000 hosted servers from a single flaw. That\u2019s what secrets sprawl actually costs when it intersects with infrastructure that\u2019s more centralized and more automated than the credentials scattered across it were ever designed to be.<\/span><\/p>\n<p><span>Two other findings from the same report should reshape how security teams think about the <\/span><i><span>shape<\/span><\/i><span> of this problem, not just its size. First, internal repositories are six times more likely than public ones to contain hardcoded secrets; the sprawl problem is worse exactly where fewer external eyes are watching. Second, and more troubling, 64% of secrets that leaked in 2022 are still valid and exploitable today. Detection without remediation and rotation isn\u2019t solving anything; it\u2019s cataloging a problem that never actually gets fixed.<\/span><\/p>\n<h3><span>Step One: Get Secrets out of Code Entirely<\/span><\/h3>\n<p><span>The starting point for any serious secrets program is removing hardcoded credentials from source control and configuration files and centralizing them in a purpose-built secrets manager \u2014 HashiCorp Vault, AWS Secrets Manager, Azure Key Vault or Google Secret Manager are the common choices, and the specific product matters less than the discipline of having exactly one control plane rather than credentials scattered across a dozen tools and files.<\/span><\/p>\n<p><span>In practice, this means infrastructure code references a secret at runtime instead of embedding the value directly:<\/span><\/p>\n<ul>\n<li><span>data \u201cvault_generic_secret\u201d \u201cdb_creds\u201d {<\/span><\/li>\n<li><span> path = \u201cdatabase\/creds\/readonly\u201d<\/span><\/li>\n<li><span>}<\/span><\/li>\n<li>\n<\/li><li><span>resource \u201caws_db_instance\u201d \u201capp\u201d {<\/span><\/li>\n<li><span> identifier = \u201cappdb\u201d<\/span><\/li>\n<li><span> username = data.vault_generic_secret.db_creds.data[\u201cusername\u201d]<\/span><\/li>\n<li><span> password = data.vault_generic_secret.db_creds.data[\u201cpassword\u201d]<\/span><\/li>\n<li><span>}<\/span><\/li>\n<\/ul>\n<p><span>The credential itself never touches version control. Terraform state still needs its own protections \u2014 state files can contain resolved secret values \u2014 but that\u2019s a narrower, more tractable problem than an organization-wide habit of pasting API keys directly into <\/span><span>.env<\/span><span> files and Terraform variables under deadline pressure.<\/span><\/p>\n<h3><span>Step Two: Enforce Least Privilege Inside the Vault Itself<\/span><\/h3>\n<p><span>Centralizing secrets in one place is necessary but not sufficient. Without access controls, a single compromised service account can retrieve far more than it should ever need, turning one small breach into a much larger one. Fine-grained policies scoped to exactly what each service or role requires are what actually limit the blast radius:<\/span><\/p>\n<ul>\n<li><span>path \u201cdatabase\/creds\/production\u201d {<\/span><\/li>\n<li><span> capabilities = [\u201cread\u201d]<\/span><\/li>\n<li><span> allowed_parameters = {<\/span><\/li>\n<li><span> \u201crole\u201d = [\u201creadonly\u201d]<\/span><\/li>\n<li><span> }<\/span><\/li>\n<li><span>}<\/span><\/li>\n<\/ul>\n<p><span>The principle here is simple and easy to state but consistently hard to enforce in practice: A service that only ever needs read access to a database should have no path, under any policy, to a credential capable of writing to it. Every broad grant made \u2018just in case\u2019 during an incident and never walked back afterward is exactly the kind of standing risk that GitGuardian\u2019s \u201c64% still valid\u201d finding describes at scale.<\/span><\/p>\n<h3><span>Step Three: Make Secrets Short-Lived by Default<\/span><\/h3>\n<p><span>Static, long-lived secrets are dangerous specifically because they don\u2019t expire on their own. A credential leaked once in 2022 that nobody rotated is, per the data above, still a live risk in 2026. Dynamic secrets flip this: Instead of a fixed, standing credential, the secrets manager generates a short-lived one on demand, tied to a specific request, that expires automatically.<\/span><\/p>\n<p><span>HashiCorp Vault\u2019s database and cloud secrets engines are a common way to implement this \u2014 for example, generating a temporary AWS IAM identity scoped to a single task, valid for a bounded window, rather than handing a service a permanent access key it holds indefinitely. For secrets that genuinely can\u2019t be made dynamic (some third-party API keys, for instance), a rotation strategy modeled on blue\/green deployments works well in practice: Maintain both a current and a next-version secret, validate that the new one works end-to-end, then cut over and revoke the old one rather than rotating in place and hoping nothing breaks mid-transition.<\/span><\/p>\n<p><span>The goal in both cases is the same: Shrink the window during which a leaked credential is actually useful to an attacker, since detection and remediation alone clearly aren\u2019t keeping pace with the volume of secrets being created.<\/span><\/p>\n<h3><span>Step Four: Assume You\u2019ll Need to Prove What Happened<\/span><\/h3>\n<p><span>A secrets manager without audit logging tells you what secrets exist, but nothing about who accessed them, when or whether that access was expected. Enabling audit devices \u2014 piping access logs to a SIEM, Splunk instance or equivalent \u2014 turns \u201cwe think this credential might be compromised\u201d into \u201cwe can see exactly when and how it was used,\u201d which is the difference between a fast, contained response and a slow, uncertain one.<\/span><\/p>\n<p><span>This matters more, as AI agents get direct access to infrastructure. An agent with a standing credential and no logged trail of what it did with that credential is a much harder incident to investigate than one whose every access is recorded against a specific task and timestamp.<\/span><\/p>\n<h3><span>A Practical Playbook<\/span><\/h3>\n<p><span>Bringing this together into a sequence a team can actually execute:<\/span><\/p>\n<p><span>Discover What\u2019s Already Exposed: Run a secrets-scanning tool such as GitGuardian or TruffleHog across your full repository history, not just the current branch. Leaked secrets frequently persist in old commits long after the file that contained them was \u2018fixed\u2019. Given that 64% of secrets leaked in 2022 are still valid, assume old findings are still live until you\u2019ve confirmed otherwise.<\/span><\/p>\n<ol>\n<li><span>Remove and Rotate, Don\u2019t Just Delete: Purging a secret from source history without rotating the underlying credential leaves the exposure intact \u2014 the value is already out, likely already scraped and cached elsewhere. Rotate first, then clean the history<\/span><\/li>\n<li><span>Stand up a Single Secrets Manager: Consolidate into one control plane rather than a patchwork of environment variables, CI\/CD secret stores and cloud-provider-specific tools that nobody has a complete inventory of.<\/span><\/li>\n<li><span>Apply Least-Privilege Policies From Day One: Default every new service account and role to the narrowest access that lets it function and require an explicit, logged decision to widen it \u2014 never the reverse.<\/span><\/li>\n<li><span>Convert Static Secrets to Dynamic Ones Wherever the Secrets Engine Supports It: Start with the highest-value targets. Database credentials and cloud IAM roles are usually both the most common and the most damaging if leaked.<\/span><\/li>\n<li><span>Automate Rotation for Everything That Can\u2019t be Made Dynamic: Implement scheduled rotation, blue\/green cutover and automatic revocation of the previous version once the new one is confirmed to be working.<\/span><\/li>\n<li><span>Enable Audit Logging and Route it Somewhere Your Security Team Actually Monitors: A log nobody reviews provides the appearance of visibility without the substance of it.<\/span><\/li>\n<li><span>Pay Specific Attention to AI Tooling: Treat MCP configuration files, AI agent service accounts and CLI-passed API keys as a distinct category worth auditing on their own, given how disproportionately fast that category of leak is growing.<\/span><\/li>\n<li><span>Revisit the Entire Inventory Quarterly: Secrets sprawl isn\u2019t a project with an end date. GitGuardian\u2019s own data shows the problem accelerating year over year, which means a program that isn\u2019t actively maintained will fall behind, not stay even.<\/span><\/li>\n<\/ol>\n<h3><span>Conclusion<\/span><\/h3>\n<p><span>Secrets sprawl persists not because teams don\u2019t know hardcoded credentials are risky, but because detection alone doesn\u2019t fix anything. A scanner that finds a leaked key changes nothing if nobody rotates it, and the data shows that gap is exactly where organizations are failing. Centralizing secrets in a single control plane, enforcing least privilege inside it, converting static credentials to short-lived dynamic ones and treating audit logging as non-negotiable together close that gap in a way that scanning by itself never will. <\/span><\/p>\n<p><span>With breach costs at a record $4.99 million globally and secrets exposure still growing faster than the developer population producing it, the return on actually finishing this work \u2014 not just starting it \u2014 has never been more direct.<\/span><\/p>\n<p><a href=\"https:\/\/devops.com\/secrets-sprawl-and-rotation-a-practical-vault-management-playbook\/\" target=\"_blank\" class=\"feedzy-rss-link-icon\">Read More<\/a><\/p>\n<p>\u200b<\/p>","protected":false},"excerpt":{"rendered":"<p>In 2025 alone, security firm GitGuardian detected 28.65 million new hardcoded secrets exposed in public GitHub commits \u2014 a 34% [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":5256,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[5],"tags":[],"class_list":["post-5255","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devops"],"_links":{"self":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/5255","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/comments?post=5255"}],"version-history":[{"count":0,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/5255\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media\/5256"}],"wp:attachment":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media?parent=5255"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/categories?post=5255"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/tags?post=5255"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}