Overview of Secret Manager
Secret Manager allows you to store and access secrets as binary blobs. It uses IAM permissions to grant access to the secrets and be able to manage them. Secret Manager is used for applications running on Google Cloud to store information such as database passwords, API keys, or certificates.
Note
Cryptographic keys should not be stored in Secret Manager. Cloud KMS is a better service since it allows you to encrypt the key material.
Before we start using Secret Manager, let us go over some core concepts. This will help you understand how Secret Manager works so you can make the right decision for your workloads.
Secret Manager concepts
Let us look at some key definitions related to Secret Manager as defined in the Google Cloud documentation:
- Secret: A secret is an object at the project level that stores a collection of metadata and secret versions. The metadata includes replication locations, labels, and permissions.
- Version: A...