SecurityDevOps/CloudHigh signal
Secrets Management
Also written as Vault, AWS Secrets Manager
Securely storing and controlling access to sensitive credentials (API keys, passwords, certificates) instead of hardcoding them into source code or config files.
Think of it like
Like a hotel safe for valuables instead of leaving them in plain sight on the dresser — accessible when needed, but not just lying around.
Junior or senior?
Junior sounds like
Knows secrets shouldn't be hardcoded but hasn't fixed one.
Senior sounds like
Has actually found a hardcoded secret in a codebase and can describe what they did about it.
Ask them
“Have you ever found a hardcoded secret in a codebase? What did you do about it?”