CuraDevOps

tag: Secrets-Management · 7 items

2026-09-02 · HashiCorp Blog · source ↗ #vault#secrets-management#agentic-ai
  • Platform/SRE — Plan: If your org runs Vault Enterprise and is deploying AI agent workloads, this GA feature adds purpose-built IAM controls worth evaluating this quarter; no forced migration or deadline, but assess whether your current Vault version and license tier expose it.
  • CI/CD — Skip
  • Leader — Learn: This signals Vault Enterprise is extending its security model to cover AI agent identities; worth noting if AI agent adoption is on the roadmap and the org is already standardized on Vault Enterprise, but no strategy or contract decision is required now.
  • Signals: GA announcement
  • Platform/SRE — Learn: Interesting pattern for zero-trust mainframe access using Boundary workers, but no deadline or GA capability change — worth evaluating if mainframes are in scope for the platform.
  • CI/CD — Skip
  • Leader — Skip
  • Platform/SRE — Plan: If your platform integrates Cisco Security Cloud Control or Netskope, you can now remove any custom Lambda rotation logic and let Secrets Manager handle scheduled credential rotation natively; worth scheduling a migration this quarter for affected integrations.
  • CI/CD — Skip
  • Leader — Skip
2026-08-12 · AWS What's New · source ↗ #secrets-management#jenkins#sonarqube
  • Platform/SRE — Learn: New GA capability for automating credential rotation without custom code; worth knowing for teams already using Secrets Manager managed external secrets, but no operational urgency.
  • CI/CD — Plan: Teams using Jenkins or SonarQube with AWS Secrets Manager can now automate token rotation natively — schedule evaluation and adoption to reduce manual credential lifecycle work and lower the risk of stale tokens in pipelines.
  • Leader — Skip
  • Platform/SRE — Plan: This GA expansion lets platform teams consolidate Kubernetes (ESO), Terraform/OpenTofu, and Vault CLI secrets into a single OpenBao-backed store — worth evaluating this quarter as a replacement for fragmented per-tool secret stores, with no forcing deadline yet.
  • CI/CD — Learn: GitLab CI/CD secret support landed in v19.0 already; the new ESO and Terraform integrations are primarily platform-side — no pipeline changes required today, but the unified API surface is worth noting for future supply-chain design.
  • Leader — Learn: The consolidated single-store model (one audit trail, one access model across Kubernetes, IaC, and pipelines) is worth tracking as a vendor-consolidation data point when revisiting secrets-toolchain standards, but no pricing or license forcing function exists yet.
  • Platform/SRE — Skip
  • CI/CD — Learn: Vendor-authored post highlighting how AI coding agents can leak credentials into build/deploy contexts; worth evaluating your secret isolation controls if agents touch pipelines, but no concrete deadline or confirmed compromise here.
  • Leader — Learn: Surfaces a real risk category—AI agent access to secrets in the software supply chain—worth factoring into your AI tooling policy and golden-path standards, though this is Docker marketing with no specific incident or actionable deadline.
2026-07-23 · AWS What's New · source ↗ #secrets-management#eventbridge#aws
  • Platform/SRE — Plan: New GA capability removes the CloudTrail-parsing workaround for secret rotation events; evaluate adding EventBridge rules this quarter to auto-refresh credential caches or trigger service restarts on rotation, reducing the lag window between rotation and downstream adoption.
  • CI/CD — Learn: Could inform future pipeline designs that need to react to secret rotation (e.g., invalidating cached build credentials), but no current pipeline change is required and no deprecation is introduced.
  • Leader — Skip