Secrets & Key Management across clouds

Secret stores and KMS (Key Vault, Secrets Manager, KMS, Vault) with verified, least-privilege modules.

23 verified modules, 5 of them live-tested apply→verify→destroy; the rest are static-validated, live-test pending.

Compare by provider

ProviderModuleVerification
Alibaba CloudA KMS Key that Rotates and Cannot Be Scheduled for Deletionstatic-validated
Alibaba CloudA KMS Secret Encrypted with Your Key, with a Recovery Window Before It Is Gonestatic-validated
AWSKMS Key with Policy Patterns✓ live-tested
AWSSecrets Manager Secret✓ live-tested
AzureAzure Key Vault✓ live-tested
ExoscaleA KMS Key Placed on Purpose with What the Service Lacks Written Downstatic-validated
Google CloudCloud KMS Keyring & Keys✓ live-tested
Google CloudSecret Manager Secrets✓ live-tested
Huawei CloudA CSMS Secret Encrypted with Your KMS Key, with an Expirystatic-validated
Huawei CloudA KMS Key that Rotates with the Longest Deletion Windowstatic-validated
IBM CloudA Root Key that Rotates and Takes Two People to Deletestatic-validated
IBM CloudA Secret Group and an Arbitrary Secret in an Instance You Already Pay Forstatic-validated
Multi-cloud & platform-agnosticA KV v2 Engine that Keeps Versions and Refuses Blind Overwritesstatic-validated
Multi-cloud & platform-agnosticAppRole Roles that Bind to Somewhere Specific and Issue Secret IDs that Expirestatic-validated
Multi-cloud & platform-agnosticDynamic PostgreSQL Credentials with the Root Password Rotated Awaystatic-validated
Multi-cloud & platform-agnosticOIDC Auth Whose Roles Admit the Claims You Namestatic-validated
Multi-cloud & platform-agnosticTransit Keys that Rotate and Cannot Be Deleted or Exportedstatic-validated
Multi-cloud & platform-agnosticVault Policies & Authstatic-validated
Oracle CloudVault, Keys & Secretsstatic-validated
OVHcloudSecrets that Expire on a Date You Setstatic-validated
ScalewaySecrets that Cannot Be Deleted in One Call and Versions that Expirestatic-validated
Tencent CloudA KMS Key that Rotates with the Longest Deletion Windowstatic-validated
Tencent CloudA Secret and Its Version, Encrypted with Your KMS Key, with a Recovery Windowstatic-validated

How to choose

Use a KMS for encryption keys and envelope encryption; use a secrets manager for credentials with rotation. Vault fits multi-cloud or dynamic-secret needs.

When not to use

Never substitute environment variables or config files for these - but also do not store large blobs in a secrets store; it is not object storage.

Other solutions