Secrets store (vault): what it is and how it is attacked
The safe where passwords, keys and certificates are kept.
Also known as
- vault
- secrets manager
- credential store
- password safe
Typing any of them into the editor finds this object.
Why it matters on a security diagram
Reaching it converts one compromised machine into access to everything it holds credentials for.
How it gets attacked, and what reduces it
How it gets attacked
- Application credentials found in code or configuration instead
- Access tokens reused far beyond their intended scope
What reduces it
- Grant access per secret rather than at the safe, so one application cannot read every credential
- Prefer platform-issued machine identities, which remove the stored credential entirely
- Rotate on a schedule and alert on a secret fetched from an unexpected place
Where it sits
- Group
- Security and edge · The things that sit in front of something else and check what is trying to reach it.
- Whose side, by default
- Ours · Belongs to the organisation the diagram is about.
- Catalogue identifier
- secrets-store
Reviewed . CC BY 4.0.
Others in security and edge
- FirewallNGFW · packet filterDecides which connections are allowed between two networks.
- Web app shieldWAF · web application firewallChecks visits to your website and blocks the ones that look like an attack.
- Outbound web filterforward proxy · secure web gateway · SWG · web filter · web proxyChecks and records everything staff and servers send out to the internet.
- Traffic splitterload balancer · LB · ADCSpreads incoming requests across several servers.
- Global content cacheCDN · content delivery network · edge cacheCopies your content to servers worldwide so pages load faster.
- API front doorAPI gatewayOne controlled entrance for the automatic requests other software makes of yours, without a person involved.
- Endpoint protectionEDR · antivirus · AV · XDRSoftware on each computer watching for hostile behaviour.
- Log collectorSIEM · log server · syslogCollects the records of what happened, from every computer and system, into one place.
- Encryption key serviceKMS · key management service · key vault · HSM · customer-managed keyThe service that holds the keys used to scramble stored data, and decides who may use them.
- Cloud activity recordCloudTrail · activity log · control plane log · audit trailThe provider's own record of every change made to the cloud, and of who made it.
The security and edge group lists all 11 of them side by side.
Secrets store on your own diagram
Open the editor, press N, and type vault. The object is placed and connected to whatever was selected, and Tab adds the next one already joined to it. Nothing is uploaded: the page is served with a Content Security Policy that forbids the browser from making any outbound request at all.
Open the diagram maker