<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Secrets-Management on CuraDevOps</title><link>https://curadevops.metacog.co.kr/tags/secrets-management/</link><description>Recent content in Secrets-Management on CuraDevOps</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 02 Sep 2026 14:51:34 +0000</lastBuildDate><atom:link href="https://curadevops.metacog.co.kr/tags/secrets-management/index.xml" rel="self" type="application/rss+xml"/><item><title>HashiCorp Boundary extends identity-based access to mainframes</title><link>https://curadevops.metacog.co.kr/insights/2026-09-02-secure-mainframe-access-with-hashicorp-boundary/</link><pubDate>Wed, 02 Sep 2026 14:51:34 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-09-02-secure-mainframe-access-with-hashicorp-boundary/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Learn:&lt;/strong> Interesting pattern for zero-trust mainframe access using Boundary workers, but no deadline or GA capability change — worth evaluating if mainframes are in scope for the platform.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>HashiCorp Vault Agentic IAM reaches GA in Vault Enterprise</title><link>https://curadevops.metacog.co.kr/insights/2026-09-02-hashicorp-vault-agentic-iam-is-now-generally-available/</link><pubDate>Wed, 02 Sep 2026 14:51:34 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-09-02-hashicorp-vault-agentic-iam-is-now-generally-available/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> If your org runs Vault Enterprise and is deploying AI agent workloads, this GA feature adds purpose-built IAM controls worth evaluating this quarter; no forced migration or deadline, but assess whether your current Vault version and license tier expose it.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> This signals Vault Enterprise is extending its security model to cover AI agent identities; worth noting if AI agent adoption is on the roadmap and the org is already standardized on Vault Enterprise, but no strategy or contract decision is required now.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> GA announcement&lt;/li>
&lt;/ul></description></item><item><title>AWS Secrets Manager adds native rotation for Cisco Security Platform and Netskope tokens</title><link>https://curadevops.metacog.co.kr/insights/2026-08-26-aws-secrets-manager-adds-managed-external-secrets-support-fo/</link><pubDate>Wed, 26 Aug 2026 11:21:00 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-26-aws-secrets-manager-adds-managed-external-secrets-support-fo/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> If your platform integrates Cisco Security Cloud Control or Netskope, you can now remove any custom Lambda rotation logic and let Secrets Manager handle scheduled credential rotation natively; worth scheduling a migration this quarter for affected integrations.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>AWS Secrets Manager adds managed rotation for Jenkins and SonarQube tokens</title><link>https://curadevops.metacog.co.kr/insights/2026-08-12-aws-secrets-manager-adds-managed-external-secrets-support-fo/</link><pubDate>Wed, 12 Aug 2026 11:40:52 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-12-aws-secrets-manager-adds-managed-external-secrets-support-fo/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Learn:&lt;/strong> New GA capability for automating credential rotation without custom code; worth knowing for teams already using Secrets Manager managed external secrets, but no operational urgency.&lt;/li>
&lt;li>&lt;strong>CI/CD — Plan:&lt;/strong> Teams using Jenkins or SonarQube with AWS Secrets Manager can now automate token rotation natively — schedule evaluation and adoption to reduce manual credential lifecycle work and lower the risk of stale tokens in pipelines.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>GitLab Secrets Manager adds ESO, Terraform, and API support via OpenBao</title><link>https://curadevops.metacog.co.kr/insights/2026-08-07-gitlab-secrets-manager-adds-eso-terraform-api-support/</link><pubDate>Fri, 07 Aug 2026 00:23:45 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-07-gitlab-secrets-manager-adds-eso-terraform-api-support/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> This GA expansion lets platform teams consolidate Kubernetes (ESO), Terraform/OpenTofu, and Vault CLI secrets into a single OpenBao-backed store — worth evaluating this quarter as a replacement for fragmented per-tool secret stores, with no forcing deadline yet.&lt;/li>
&lt;li>&lt;strong>CI/CD — Learn:&lt;/strong> GitLab CI/CD secret support landed in v19.0 already; the new ESO and Terraform integrations are primarily platform-side — no pipeline changes required today, but the unified API surface is worth noting for future supply-chain design.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The consolidated single-store model (one audit trail, one access model across Kubernetes, IaC, and pipelines) is worth tracking as a vendor-consolidation data point when revisiting secrets-toolchain standards, but no pricing or license forcing function exists yet.&lt;/li>
&lt;/ul></description></item><item><title>Docker: AI coding agents risk exposing secrets in supply chain attacks</title><link>https://curadevops.metacog.co.kr/insights/2026-07-29-coding-agent-horror-stories-the-29-million-secret-problem/</link><pubDate>Wed, 29 Jul 2026 12:56:53 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-29-coding-agent-horror-stories-the-29-million-secret-problem/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Learn:&lt;/strong> Vendor-authored post highlighting how AI coding agents can leak credentials into build/deploy contexts; worth evaluating your secret isolation controls if agents touch pipelines, but no concrete deadline or confirmed compromise here.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Surfaces a real risk category—AI agent access to secrets in the software supply chain—worth factoring into your AI tooling policy and golden-path standards, though this is Docker marketing with no specific incident or actionable deadline.&lt;/li>
&lt;/ul></description></item><item><title>AWS Secrets Manager natively publishes rotation events to EventBridge</title><link>https://curadevops.metacog.co.kr/insights/2026-07-23-aws-secrets-manager-now-publishes-secret-update-notification/</link><pubDate>Thu, 23 Jul 2026 12:19:57 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-23-aws-secrets-manager-now-publishes-secret-update-notification/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> New GA capability removes the CloudTrail-parsing workaround for secret rotation events; evaluate adding EventBridge rules this quarter to auto-refresh credential caches or trigger service restarts on rotation, reducing the lag window between rotation and downstream adoption.&lt;/li>
&lt;li>&lt;strong>CI/CD — Learn:&lt;/strong> Could inform future pipeline designs that need to react to secret rotation (e.g., invalidating cached build credentials), but no current pipeline change is required and no deprecation is introduced.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>