Prompt
What should I use to keep secrets out of GitHub repos?
Latest observation
Oct 3, 2026
OpenAI APIWeb search: off
Use a secrets manager, not GitHub, for anything sensitive.
Good options:
- Cloud-native secrets managers
- AWS Secrets Manager / SSM Parameter Store
- Azure Key Vault
- Google Secret Manager
- Platform/CI secret storage
- GitHub Actions Secrets for CI-only values
- Kubernetes Secrets if you’re deploying to K8s
- Dedicated tools
- HashiCorp Vault
- 1Password Secrets Automation
- Doppler
- Infisical
Best practice:
- Keep secrets out of code and repos
- Load them at runtime via environment variables or secret injection
- Use short-lived credentials where possible
- Rotate secrets regularly
- Add secret scanning and pre-commit checks to catch leaks early
If you want, I can recommend the best choice based on your stack (AWS/Azure/GCP, Docker, Kubernetes, GitHub Actions, etc.).