| name | moai-security-secrets |
| version | 4.0.0 |
| status | stable |
| description | Enterprise Skill for advanced development |
| allowed-tools | Read, Bash, WebSearch, WebFetch |
moai-security-secrets: Secret Management & Rotation
Secure Credential Storage, Rotation & Distribution
Trust Score: 9.9/10 | Version: 4.0.0 | Enterprise Mode | Last Updated: 2025-11-12
Overview
Secret management is critical infrastructure: API keys, database passwords, and encryption keys must be stored securely, rotated regularly, and distributed safely. This Skill covers HashiCorp Vault, .env security, and secrets rotation patterns.
When to use this Skill:
- Managing database passwords and API keys
- Rotating secrets automatically
- Implementing zero-knowledge architecture
- Distributing secrets to multiple services
- Storing encryption keys securely
- Preventing hardcoded credentials
- Implementing secret versioning
- Building compliance-ready secret systems
- Using Sealed Secrets in Kubernetes
Level 1: Secret Management Principles
Secret Types & Storage
SECRET TYPES:
├─ Credentials (passwords, API keys, tokens)
├─ Cryptographic Keys (encryption, signing)
├─ Connection Strings (database, message queues)
├─ Certificates (TLS, client auth)
└─ OAuth Tokens (access tokens, refresh tokens)
STORAGE HIERARCHY:
1. Vault System (HashiCorp Vault, AWS Secrets Manager)
2. Environment Variables (via secret injection)
3. Configuration Files (.env - local dev only)
4. Memory (never disk, clear after use)
5. NEVER: Hardcoded, version control, logs
Secrets Lifecycle
Generate → Distribute → Rotate → Revoke → Destroy
↓ ↓ ↓ ↓ ↓
Secure Encrypted Schedule Immediate Wipe
Token Channel (30-90d) (breach) Keys
Rotation Strategy
| Type | Frequency | Grace Period | Method |
|---|
| API Keys | 90 days | 24 hours | Generate new, deprecate old |
| Database Passwords | 30 days | 48 hours | New password, app restart |
| TLS Certificates | 30 days before expiry | N/A | Automated renewal |
| Session Secrets | 24 hours | Immediate | Rotate all sessions |
| Encryption Keys | On breach | N/A | Re-encrypt all data |
Level 2: Implementation Patterns
HashiCorp Vault Integration
Vault Server Setup:
wget https://releases.hashicorp.com/vault/1.18.0/vault_1.18.0_linux_amd64.zip
unzip vault_1.18.0_linux_amd64.zip
vault server -config=/etc/vault/config.hcl
vault operator init
vault operator unseal [key1] [key2] [key3]
vault secrets enable -path=app kv-v2
vault secrets enable database
Node.js Vault Client:
const vault = require('@hashicorp/vault-client');
const client = new vault.ApiClient({
endpoint: process.env.VAULT_ADDR,
token: process.env.VAULT_TOKEN
});
async function getSecret(path) {
try {
const response = await client.read(`secret/data/${path}`);
return response.data.data;
} catch (err) {
console.error('Vault error:', err);
throw err;
}
}
async function setSecret(path, data) {
await client.write(`secret/data/${path}`, {
data: data
});
}
async function generateDBPassword(role) {
const cred = await client.read(`database/creds/${role}`);
{
: cred..,
: cred..,
: cred.
};
}
() {
newKey = crypto.().();
(, { : newKey });
(appName, newKey);
(, {
: ,
: ()
});
}
() {
response = client...({
: process..,
: process..
});
response..;
}
.env Security (Development)
NEVER commit secrets to version control:
.env
.env.local
.env.*.local
.env.prod
.env.backup
secrets/
keys/
Environment Variable Validation:
const z = require('zod');
const envSchema = z.object({
NODE_ENV: z.enum(['development', 'production']).default('development'),
DATABASE_URL: z.string().url(),
DATABASE_PASSWORD: z.string().min(16),
API_KEY: z.string().min(32),
ENCRYPTION_KEY: z.string().length(64),
JWT_SECRET: z.string().min(32),
OAUTH_CLIENT_ID: z.string(),
OAUTH_CLIENT_SECRET: z.string(),
VAULT_ADDR: z.string().url().optional(),
VAULT_TOKEN: z.string().optional()
});
export const env = envSchema.parse(process.env);
Object.keys(env).( {
(key.() || key.() || key.()) {
.(env, key, {
() {
;
}
});
}
});
Secrets Rotation Scheduler
const cron = require('node-cron');
const vault = require('@hashicorp/vault-client');
class SecretsRotationJob {
constructor(vaultClient) {
this.vault = vaultClient;
this.rotationSchedules = [
{ path: 'app/database-password', schedule: '0 2 * * 0', ttl: '30d' },
{ path: 'app/api-keys', schedule: '0 3 * * SUN', ttl: '90d' },
{ path: 'app/session-secret', schedule: '0 * * * *', ttl: '24h' }
];
}
start() {
this.rotationSchedules.forEach(({ path, schedule }) => {
cron.schedule(schedule, () => {
this.rotateSecret(path).catch(err => {
console.error(`Rotation failed for :`, err);
.(path, err);
});
});
});
}
() {
.();
newSecret = .(path);
..(, newSecret);
..(, {
: ,
:
});
.(path, );
.(path, );
( () => {
..();
}, );
}
() {
.();
..(, { : });
emergency = .(path);
..(, emergency);
.(path, );
.(path, );
.(path);
}
() {
(path.()) {
{
: ().().(),
: (),
: (.() + * * * )
};
}
(path.()) {
{
: ,
: ()
};
}
{};
}
() {
services = .(path);
( service services) {
..(, {
path,
version,
: ()
}, { : service });
}
}
() {
maxRetries = ;
retries = ;
(retries < maxRetries) {
adopted = .(path, version);
(adopted === ) {
.();
;
}
.();
( (r, ));
retries++;
}
}
() {
..({
: ,
: ,
: error.,
:
});
}
}
rotationJob = (vaultClient);
rotationJob.();
Kubernetes Sealed Secrets
kubectl apply -f https://github.com/bitnami-labs/sealed-secrets/releases/download/v0.23.1/controller.yaml
kubectl create secret generic my-secret \
--from-literal=password=mypassword \
--dry-run=client -o yaml > secret.yaml
kubeseal -f secret.yaml -w sealed-secret.yaml
kubectl apply -f sealed-secret.yaml
apiVersion: v1
kind: Pod
metadata:
name: my-app
spec:
containers:
- name: app
image: my-app:latest
env:
- name: PASSWORD
valueFrom:
secretKeyRef:
name:
Level 3: Zero-Knowledge Architecture
class ZKAuth {
async register(email, password) {
const salt = crypto.randomBytes(16);
const commitment = hash(hash(password) + salt);
await fetch('/auth/register', {
method: 'POST',
body: JSON.stringify({ email, commitment, salt })
});
}
async login(email, password) {
const challenge = await fetch(`/auth/challenge?email=${email}`);
const response = hmac(sha256(password), challenge);
const result = await fetch('/auth/login', {
method: 'POST',
body: JSON.stringify({ email, response })
});
result.();
}
}
Reference
Official Resources
Tools & Libraries
Common Vulnerabilities
- CWE-798: Hard-coded Credentials
- CWE-321: Use of Hard-coded Cryptographic Key
- CWE-798: Hardcoded Passwords
- OWASP A02:2021: Cryptographic Failures
Version: 4.0.0 Enterprise
Skill Category: Security (Secret Management)
Complexity: Advanced
Time to Implement: 4-6 hours
Prerequisites: DevOps, Kubernetes basics, cryptography concepts