Skip to content

Add comprehensive secrets management tools guide for 2025 #15315

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Draft
wants to merge 6 commits into
base: master
Choose a base branch
from

Conversation

asafashirov
Copy link
Contributor

Summary

  • Create comprehensive evergreen article covering 25+ secrets management tools across 6 key categories
  • Strategic positioning of Pulumi ESC as premier secrets orchestration platform
  • Paragraph-centric content with natural flow (not list-heavy format)
  • Internal Pulumi.com links throughout (no competitor external links)
  • Balanced educational coverage while naturally guiding readers toward Pulumi ESC

Content Overview

The guide covers:

  • Secrets Orchestration Platforms (led by Pulumi ESC)
  • Enterprise Secrets Vaults (HashiCorp Vault, CyberArk, Akeyless)
  • Cloud-Native Secrets Managers (AWS, Azure, GCP)
  • Developer-Focused Tools (1Password, Bitwarden)
  • Application Security & Scanning (GitGuardian, TruffleHog)
  • Specialized & Integration Tools (External Secrets Operator, etc.)

Strategic Positioning

  • Positions Pulumi ESC as the most advanced "secrets broker" and orchestration platform
  • Emphasizes configuration-as-code approach as the future of secrets management
  • Natural progression from traditional vaults → cloud-native → orchestration platforms
  • Educational tone that builds authority while guiding toward Pulumi ESC as optimal choice

Test Plan

  • Content flows naturally without excessive bullet points
  • Pulumi ESC positioned prominently with comprehensive feature coverage
  • All external competitor links removed
  • Strategic internal Pulumi.com links added throughout
  • Markdown lint and Prettier formatting passes
  • Review content for accuracy and messaging alignment
  • Verify all internal links work correctly
  • SEO review for keyword optimization

@pulumi-bot
Copy link
Collaborator

@pulumi-bot
Copy link
Collaborator

Create evergreen blog post covering 25+ secrets management tools across 6 categories with strategic Pulumi ESC positioning as premier secrets orchestration platform. Features paragraph-centric content, internal Pulumi.com links, and balanced educational coverage while naturally guiding readers toward ESC as optimal choice for modern configuration-as-code workflows.
- Update publication date from January 14, 2025 to July 1, 2025
- Remove missing meta_image reference that caused build failures

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <[email protected]>
@pulumi-bot
Copy link
Collaborator

- Update statistics with proper citations: 96% (Akeyless), 88% (Verizon DBIR), $4.88M (IBM)
- Enhance introduction with more conversational, engaging tone
- Restructure content sections for better narrative flow following technical blog best practices
- Improve paragraph-based structure over bullet lists for better readability
- Strengthen conclusion with clearer decision framework and actionable insights
- Add proper source citations for all statistical claims
@pulumi-bot
Copy link
Collaborator

Copy link
Contributor

@borisschlosser borisschlosser left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for putting this all together! That's really a comprehensive guide.
Still I added some comments and would add the following general tweaks:

  • I would not advertise other similar sized products like Doppler or Infisical. Advertising the big ones like Vault, AWS, Azure etc. should be fine as they are way more complex to handle and with this also target other customers or making customers think of using a simpler product like ESC.
  • Ensure that there is a reference to ESC (docs) in every section under "Top Features to Look for in Secrets Management Tools" to showcase ESC's capabilities


Runtime integration capabilities should extend to application frameworks like Spring Boot, Django, and Express.js, enabling developers to access secrets through familiar programming patterns. [Cloud platforms](https://www.pulumi.com/docs/clouds/) including AWS Lambda, Azure Functions, and Google Cloud Run should provide optimized secret injection with minimal performance impact. Monitoring tools, service meshes, and other infrastructure components should integrate seamlessly to provide comprehensive observability and management capabilities.

### Comprehensive Audit and Compliance Capabilities
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What does ESC support here? We should underline ESC's capabilities here by adding references to our docs as it is done in the previous sections.
I would also add some words around Bring your own key / customer managed keys here which is on the horizon for ESC: #15284

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

can you please take a look at the updated version? feel free to make edits directly in the article as a suggestion

Address PR feedback by strategically positioning Pulumi ESC throughout the
secrets management guide while maintaining educational value:

- Move ESC to top of tools list with comprehensive description
- Add ESC references to best practices, sharing, CI/CD, and compliance sections
- Highlight enterprise-grade features: audit trails, OIDC, dynamic credentials
- Emphasize performance, scalability, and cost benefits
- Include self-hosting options for data residency requirements
- Focus on enterprise solutions over smaller competing products

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <[email protected]>
asafashirov and others added 2 commits July 15, 2025 11:39
Address PR feedback by strategically enhancing ESC positioning in the blog post:

- Add enterprise-grade security and compliance features section
- Highlight performance and scalability capabilities
- Emphasize advanced key management capabilities
- Include cost-effective enterprise solution benefits
- Add self-hosting options for data residency requirements
- Reduce emphasis on smaller competing products (Doppler, Infisical)
- Focus on enterprise-grade solutions and capabilities

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <[email protected]>
@pulumi-bot
Copy link
Collaborator

@pulumi-bot
Copy link
Collaborator

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants