Building Uber’s Multi-Cloud Secrets Management Platform

Uber developed a centralized, automated, and scalable secrets management platform to address the challenges of managing over 150,000 secrets across 5,000 microservices, databases, and numerous third-party integrations. To prevent secrets sprawl and enhance security, they implemented preventive measures like a Git pre-commit hook CLI tool to block secret leaks at the source and remediation strategies including real-time and scheduled scanning of code repositories, Slack conversations, and build logs. The platform enforces a Secret Management Standard requiring all secrets to be stored in approved vaults managed by a dedicated Secrets team. Collaborations with internal stakeholders led to the development of systems like the Secure Secret eXchange (SSX), and the platform continues to evolve with features like IDE-integrated security copilots to proactively assist developers 

https://www.uber.com/en-AU/blog/building-ubers-multi-cloud-secrets-management-platform

Comments

Popular posts from this blog

Secure Vibe Coding Guide: Best Practices for Writing Secure Code

KEVIntel: Real-Time Intelligence on Exploited Vulnerabilities

OWASP SAMM Skills Framework Enhances Software Security Roles