All GCP services

GCP · Security & Identity

Secret Manager

Versioned secrets with IAM and audit.

Official docs

Overview

Secret Manager stores API keys, passwords and certs with versioning and replication policies.

When to use it

  • CI secrets
  • App config
  • Test credentials

Setup

  1. Enable API.
  2. Create secret + add version.
  3. Grant `roles/secretmanager.secretAccessor` to consumer SA.

How to use

Read secret
gcloud secrets versions access latest --secret=stripe-test-key

QA use cases

  • Inject test API keys at runtime instead of baking into images.