Title: Secrets and Key Management Version: 1.0 Owner: [TENANT_CONFIGURATION_REQUIRED — Security Architecture] Status: Draft Last reviewed: 2026-09-07 Next review: [TENANT_CONFIGURATION_REQUIRED] Reviewers: Security, DevOps
Defines how secrets (credentials, API keys, signing keys, encryption keys) are stored, accessed, rotated, and never exposed. See .env.example for the reference variable list (all secret values are references, never literals).
config/ files reference secrets by key (kv://...), never by value — enforced by the .gitignore rules and CI secret-scanning (ci-cd-quality-gates.md).| Category | Examples | Rotation cadence (default — [TENANT_CONFIGURATION_REQUIRED]) |
|---|---|---|
| Database credentials | DB user/password or managed-identity config | 90 days or on-demand upon suspected compromise |
| Object storage credentials | Storage account keys/SAS | 90 days |
| Model provider API keys | LLM provider key | 90 days |
| Identity provider client secret | OIDC client secret | 180 days |
| MCP shared auth secret | OAuth client credentials per MCP server | 90 days |
| Webhook signing secrets | Per-vendor HMAC secret | 180 days or per vendor requirement |
| Field-level encryption keys | Column encryption key | Per KMS key-rotation policy, versioned (old key retained for decrypt-only) |
Data-encryption keys are managed by the KMS provider, with envelope encryption: a data-encryption key (DEK) encrypts the data, and a key-encryption key (KEK) in the vault encrypts the DEK. KEK rotation does not require re-encrypting all data; DEK rotation follows a scheduled re-encryption job.
Only the specific service/workload that needs a secret is granted access (least privilege); no shared “god” credential across services. Access to read/rotate secrets is itself audited (see audit-log-specification.md).
Suspected secret compromise triggers the incident-response-runbook.md with immediate rotation of the affected secret and audit-log review of its usage window.
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | 2026-09-07 | Documentation package generation | Initial creation |