Lesson 4: Secrets Management (HashiCorp Vault & OIDC)
🧠 The Concept (Explain Like I'm 5)
Never hide your house key under the doormat (Hardcoding passwords in Git). Instead, hire a highly secure bank teller (Vault). When you need to enter the house, you prove who you are to the teller, and they hand you a key that magically melts after 15 minutes (Dynamic Secrets).
🏢 The Enterprise Context
- Dynamic Secrets: Instead of creating a permanent database password, Vault dynamically creates a PostgreSQL user/password on-the-fly when a microservice asks for it, and deletes it an hour later.
- OIDC (OpenID Connect): CI/CD pipelines (like GitHub Actions) shouldn't use long-lived AWS IAM Access Keys. Instead, AWS trusts GitHub cryptographically via OIDC, granting temporary access only for specific repositories.
🗺️ Visual Architecture: GitHub Actions OIDC to AWS
sequenceDiagram
autonumber
participant GH as GitHub Actions
participant IdP as GitHub OIDC Provider
participant AWS as AWS IAM (Trusts IdP)
GH->>IdP: Request OIDC Token (JWT)
IdP-->>GH: Returns Signed Token (repo:my-org/my-app)
GH->>AWS: AssumeRoleWithWebIdentity (Sends Token)
Note over AWS: AWS verifies JWT signature<br/>and Repository name
AWS-->>GH: Returns Temporary STS Credentials (15 mins)
GH->>AWS: terraform apply (Using temp creds)