Hi everyone, I’ve been trying to wrap my head around a multi-cloud setup for a project at work, and I keep hitting a wall with secrets management.
We have some workloads on AWS, a few services on Google Cloud, and our legacy system is still on Azure. Right now, each team is handling secrets in their own way—some use the native vaults, others have .env files (I know, not ideal), and it’s becoming a bit of a mess to audit and rotate things securely.
I’ve been reading about AWS Secrets Manager, Azure Key Vault, and Google Secret Manager. They seem similar in concept, but I’m unsure about the practical side of using them together. Is the best practice to pick one as a central source and sync to the others? Or should we use a third-party tool like HashiCorp Vault across all three clouds?
I’m especially curious about real-world trade-offs. For example, if an app in GCP needs a database password stored in AWS Secrets Manager, does the latency of cross-cloud calls become a problem? And how do you handle the cost structure when secrets are accessed frequently from another cloud?
Any insights or experiences you could share would be really helpful. I’m eager to learn from what’s worked (or hasn’t) for others.