Skip to main content

Secret Rotation and Management

Learn how to rotate secrets safely, organize them effectively, and manage per-environment credentials.

Why Rotate Secrets?

Security reasons:
  • Limit blast radius if compromised
  • Meet compliance requirements (PCI DSS, SOC 2)
  • Best practice for production systems
Recommended schedule:
  • Critical secrets (production API keys): Every 30 days
  • Standard secrets: Every 90 days
  • Database passwords: Every 90 days
  • OAuth tokens: When revoked by provider

Safe Rotation Process

Step-by-Step

1. Create new secret with different name:
2. Update routes to use new secret:
3. Test thoroughly in staging first 4. Deploy to production 5. Monitor for 24-48 hours 6. Delete old secret when confirmed working

Why This Works

  • Zero downtime
  • Easy rollback (keep old secret temporarily)
  • Clear audit trail

What NOT to Do

Don’t delete the old secret immediately Don’t delete immediately
  • Keep old secret for 48 hours
  • Allows rollback if issues

Environment-Specific Secrets

KnoxCall supports two approaches for managing secrets across environments: Best for: Single secret with different values per environment Create one secret with environment-specific values:
How to configure:
  1. Create a secret: stripe_api_key
  2. In the secret detail page, select environment from dropdown
  3. Add value for each environment:
    • Switch to “production” → Enter live key
    • Switch to “staging” → Enter test key
    • Switch to “development” → Enter dev key
Using in routes:
Behavior:
  • Route in “production” environment → Uses production value
  • Route in “staging” environment → Uses staging value
  • Hard fail if missing: Route returns error if secret lacks the environment value
  • No fallbacks or defaults (prevents accidental production key usage in dev)
Benefits:
  • ✅ One secret name across all environments
  • ✅ Impossible to accidentally use wrong key
  • ✅ Clear environment isolation
  • ✅ Simplified route configuration

Approach 2: Naming Convention (Legacy)

Best for: Backward compatibility or when you prefer separate secrets Create different secrets per environment:
Production route:
Staging route:
Drawbacks:
  • ❌ Must update route config when changing environments
  • ❌ Possible to reference wrong secret in wrong environment
  • ❌ More secrets to manage

Comparison

Migration tip: Use environment configs for new secrets, migrate old ones gradually

Organization Strategies

Group by Service

Group by Environment

Choose one strategy and be consistent!

Multiple Secrets in One Route

Inject multiple credentials:
All injected server-side, none exposed to client.

Cleaning Up Secrets

Find Unused Secrets

To reduce attack surface, periodically remove secrets you no longer need, such as:
  • Test or temporary secrets
  • Secrets left over from completed rotations
  • Credentials for routes that have been deleted
KnoxCall protects you from deleting a secret that is still in use: if a secret is still referenced by any route, the delete request is rejected with the name of the route that depends on it. Remove the reference from all routes first, then delete the secret.

Common Patterns

API Key Rotation

Database Password Rotation

OAuth Token Refresh

Troubleshooting

Routes failing after rotation:
  • Verify new secret value is correct
  • Check all routes were updated
  • Look for cached old values
  • Roll back to old secret if needed
“Secret not found” errors:
  • Check spelling (case-sensitive)
  • Verify secret exists in Secrets page
  • Confirm route is using correct name
Third-party API returns 401:
  • New secret value might be wrong
  • API key might be expired/revoked
  • Test secret value directly with provider

Rotation Checklist

Use this checklist for each rotation:
  • Document which routes use this secret
  • Generate new credential from provider
  • Create new secret with v2 suffix
  • Update all routes in staging
  • Test thoroughly in staging
  • Update routes in production
  • Monitor for 48 hours
  • Verify no errors
  • Delete old secret
  • Update documentation
  • Schedule next rotation (calendar)

Next Steps

  • Set up environments for per-env secrets
  • Learn about securing your routes
  • Configure monitoring and alerting
Need help? Use the support chat!

📊 Statistics

  • Level: intermediate
  • Time: 10 minutes

🏷️ Tags

secrets, security, rotation, management