We're evaluating Delinea Secret Server (cloud) for centralizing our application secrets. After integrating their SDK into a core Java service, we measured the cold start impact. The results aren't catastrophic, but they're significant.
Our baseline app start (local dev, no network calls) is ~800ms. After adding the secret retrieval step at startup—fetching a database credential and an API key—the average increased to ~920ms. That's a consistent 120ms overhead. This is for two secrets.
Breakdown of the added latency:
* ~20ms for SDK initialization and authentication.
* ~90-100ms for the actual HTTP call to the Delinea API and response parsing.
* ~1-5ms local caching check.
This matters for auto-scaling scenarios where new instances spin up under load. An extra 120ms per instance adds up. We've mitigated it by implementing lazy loading for non-critical secrets, but the core credentials needed at startup still cause this delay.
Has anyone else done similar benchmarking, particularly in containerized environments? Did you find tweaks to reduce this latency, or is this just the accepted tax for using an external secrets manager? I'm also curious if the on-premises version has a different performance profile for internal calls.