Skip to content

Lesson 4: Secrets Management (HashiCorp Vault & OIDC)

🧠 The Concept (Explain Like I'm 5)

Never hide your house key under the doormat (Hardcoding passwords in Git). Instead, hire a highly secure bank teller (Vault). When you need to enter the house, you prove who you are to the teller, and they hand you a key that magically melts after 15 minutes (Dynamic Secrets).


🏢 The Enterprise Context

  • Dynamic Secrets: Instead of creating a permanent database password, Vault dynamically creates a PostgreSQL user/password on-the-fly when a microservice asks for it, and deletes it an hour later.
  • OIDC (OpenID Connect): CI/CD pipelines (like GitHub Actions) shouldn't use long-lived AWS IAM Access Keys. Instead, AWS trusts GitHub cryptographically via OIDC, granting temporary access only for specific repositories.

🗺️ Visual Architecture: GitHub Actions OIDC to AWS

sequenceDiagram
    autonumber
    participant GH as GitHub Actions
    participant IdP as GitHub OIDC Provider
    participant AWS as AWS IAM (Trusts IdP)

    GH->>IdP: Request OIDC Token (JWT)
    IdP-->>GH: Returns Signed Token (repo:my-org/my-app)
    GH->>AWS: AssumeRoleWithWebIdentity (Sends Token)
    Note over AWS: AWS verifies JWT signature<br/>and Repository name
    AWS-->>GH: Returns Temporary STS Credentials (15 mins)
    GH->>AWS: terraform apply (Using temp creds)