secret management in on premise application

Viewed 1464

The .net core server code I'm working on is going to be hosted both in cloud infrastructure and on premises.

There are many options to handle secret management (connection strings etc...):

  • Big cloud providers are offering dedicated secret management solutions (AWS KMS, Azure Key Vault, etc..).
  • Popular orchestrators, offer also their own service (Kubernetes Secrets for example)
  • In development, we have dedicated secret management tools & process (which are nice)

But how can I store securely secrets on premise hosting? I doubt setting it as a simple variable environment is considered as safe?

2 Answers

In the On Prem setup you need to transfer the RISK to the customer who should ensure that the Master Key in this case let's say that you go for Option #3 in which case the access to the Server should be actively controlled , monitored and should be heavily restricted.

So the onus of security is to prevent any un-authorized person from getting a login access to the Server and your configuration stays secured

If your on-prem resources have internet access, I would recommend a Key Vault using client certificate authentication and IP restrictions. If you need more security, you can also use VPN.

Related