Skip to main content

GCP Secrets Blueprint

The Secrets Blueprint for Google Cloud keeps the third-party credentials of every application encrypted in Git with SOPS under Cloud KMS keys, one key per stage, and syncs them on merge into Secret Manager of each stage project, from where the External Secrets Operator delivers them to pods. It builds on the GCP Enterprise Baseline, which creates the keys in the security project. This overview section is public.

What it deploys​

The blueprint is one repository, acme-gcp-blueprint-secrets:

  • one folder per stage (sandbox, dev, staging and prod) and one encrypted YAML file per application, with flat KEY: value pairs;
  • a pull request workflow that validates every file and dry-runs the sync, with the plan as a comment;
  • a sync workflow that, on merge, writes each key of a changed stage as one Secret Manager secret with the ID <app>--<KEY> in the stage project;
  • access enforced by Cloud KMS Identity and Access Management (IAM): every engineer group can decrypt sandbox and dev, and only the platform leads and the DevOps leads can decrypt staging and prod.

The workflows sign in through Workload Identity Federation, so no service account key exists. The blueprints page describes how blueprints build on the Baseline.

Full documentation

The complete Secrets Blueprint documentation for Google Cloud is available to customers who hold it. Read the documentation overview for the concepts behind it, then sign in from the navigation bar to open the full Secrets Blueprint documentation, or contact BuiltForProd to purchase it.