QuestionQ17

Applying site reliability engineering practices

You are deploying an application that requires access to sensitive information. You need to make sure this information is encrypted and that the risk of exposure is minimized in the event of a breach. What should you do?

Explanation

The recommended approach is to keep secrets out of source code, container images, and build pipelines, and instead deliver them securely to each instance only when it is created. Using an encrypted configuration management system to inject the secret at instance creation time ensures the secret remains encrypted at rest and in transit until it is needed, limits its exposure to only the specific running instance, and avoids storing plaintext credentials in images, logs, or version control — thereby minimizing the blast radius if a breach occurs. This aligns with Google Cloud's guidance on secret management, which emphasizes retrieving secrets at runtime/deploy time through secure, access-controlled channels rather than embedding them in artifacts or exposing them broadly.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!