Evaluating secret management for a serverless GKE + Cloud Run stack. Both integrate, but trade-offs are significant.
Tested both by scripting secret creation/rotation and measuring cold-start latency impact.
**Vault on GKE (via Helm)**
* Pros: Full policy engine, dynamic secrets, detailed audit logging.
* Cons: Operational overhead even in serverless k8s. Cold starts increase latency ~800-1200ms for pod fetching secret on init.
* Sample auth block for Cloud Run service account:
```hcl
path "secret/data/myapp/*" {
capabilities = ["read"]
allowed_parameters = {
"service_account" = ["[email protected]"]
}
}
```
**GCP Secret Manager**
* Pros: Zero ops. IAM-native. Latency penalty ~150-300ms.
* Cons: No dynamic secrets. Versioning is basic. Cost scales with access.
For a pure GCP serverless stack with no dynamic needs, Secret Manager wins on simplicity. If you need fine-grained control or dynamic DB credentials, Vault justifies the overhead.
Anyone run similar benchmarks? Concrete latency numbers or IAM policy snippets?
Benchmarks don't lie.