DevOps Professional · Module 4: DevSecOps and supply chain
Secret Rotation and the Leak Drill
Leaks are when, not if. Rotation practiced in calm becomes motion in crisis: narrow the blast radius first, revoke at the source, rotate through overlap, verify everywhere, and write the audit trail while the facts are fresh.
10 min reading
Objectives
- Explain the rotation arc: narrow, add new, migrate, revoke old, verify
- Run a fictional leak drill: revoke first, rotate second, clean third
- Complete the audit trail: what leaked, where, for how long, fixed how
- Turn drill findings into rotation automation, not into longer checklists
Why this matters
A credential appears in a log aggregator and the team debates for a day whether it is exploitable while the credential stays valid. The debate is free for the attacker and expensive for everyone else. The practiced motion starts with revocation, not with analysis: kill the credential's power first, then study. The L60 lab runs this arc in a fictional credential-leak scenario with the audit trail completed; this lesson is the choreography it rehearses.
Concepts
Rotation has five motions. Narrow: scope the credential down before the crisis (least privilege per consumer, short lifetimes where supported). Add new: issue the replacement alongside the old where overlap is supported. Migrate: move consumers one by one, verifying each. Revoke old: disable at the source, confirming the old value dies everywhere it was valid. Verify: probe every consumer with the new value and confirm the old value fails. Each motion leaves evidence; the trail is the proof rotation happened, not a story told afterward.
The leak drill inverts the order at the start: revoke first (stop the bleeding), rotate second (through the normal five motions), clean third (purge exposures where possible, accepting public history cannot un-read). Analysis runs parallel to revocation, never before it. The drill is fictional and labeled: the scenario practices the motions, and no finding leaves the exercise as a production verdict.
The audit trail answers the incident questions while facts are fresh: what leaked, in which systems, valid for how long, who could have seen it, revoked when, rotated when, verified how. Write it during the drill, not after; memory edits itself within days. Drill findings convert to automation (shorter lifetimes, automatic rotation, detection rules), not to longer checklists that nobody follows twice.
Worked example
A fictional leak of a placeholder credential triggers the drill: revoke at the source first with the time noted, rotate consumers through overlap, verify new works and old fails everywhere, complete the audit trail with exposure window and actions. The times are quoted; the placeholder never resembled a real credential.
Common wrong move
Rotating by editing values in place with no overlap and no verification. Consumers break in sequence, the old value lingers somewhere unrevoked, and the rotation is declared done on hope. Overlap, migrate, revoke, verify, every time.
Quick check
An optional 4-question self-check. Answers never leave your device, are not stored, and never count toward any assessment.
Lesson feedback
No published feedback yet.
Log in and complete the lesson to leave feedback.
Exercise
Run the fictional leak drill end to end: revoke first with time noted, rotate through overlap, verify new works and old fails, complete the audit trail.
Pass criteria
The record shows revoke time, the five rotation motions with evidence, the everywhere-verified result, and the complete audit trail labeled fictional.