GCP · Security & Identity
Secret Manager
Versioned secrets with IAM and audit.
Official docsOverview
Secret Manager stores API keys, passwords and certs with versioning and replication policies.
When to use it
- CI secrets
- App config
- Test credentials
Setup
- Enable API.
- Create secret + add version.
- Grant `roles/secretmanager.secretAccessor` to consumer SA.
How to use
Read secret
gcloud secrets versions access latest --secret=stripe-test-keyQA use cases
- Inject test API keys at runtime instead of baking into images.
