Runtime Secrets Management
By Richard Augenti
Move hardcoded application secrets into a managed secret store issuing short-lived dynamic credentials, and confirm that a stolen credential expires before it is useful.
Free to browse. Takes about 60 minutes once you start.
Lab Overview
The payments-db config hardcodes the database password. It is the same in every environment, it never rotates, and everyone who has ever read the file - or the .env it was also committed to - has it permanently.
In this lab you replace that static secret with short-lived credentials minted on demand by HashiCorp Vault, watch one expire and get revoked automatically, and point the application at Vault so it stores no password at all. The end state is an application that holds no secret: it fetches one when it needs one, and that one stops working shortly afterwards.
Vault and Postgres are already running on your lab machine. Vault is in dev mode and local to the VM - no real secret store is involved.
What to Expect
- Environment: a single Ubuntu machine you connect to over SSH, with Vault (dev mode) and Postgres already running and Vault's database engine configured. No cluster required.
- Access: SSH credentials are generated for your session and shown in the workspace. They are destroyed when the lab ends.
- Dev mode: Vault runs unsealed in dev mode with a well-known root token, which is fine for a throwaway VM and is never how you would run it in production.
- Progress: your work is not saved. If the lab expires or you quit, the machine and everything on it is destroyed.
What are hands-on labs?
A lab is a real environment, not a simulation. You get a live machine with the tooling already installed, a task taken from production work, and root access to take it apart. Nothing is mocked, nothing is multiple choice. It either works or it doesn't.
Real tooling
The same commands you would run at work, on a machine that is already set up for them. No screenshots, no sandboxed toy version.
Break it freely
Everything is disposable. When the clock runs out the environment is destroyed with everything in it, so there is no reason to be careful.
Useful on Monday
Built by engineers who run these systems in production. Skills you can apply to your own stack the same week, not exam preparation.