Home / Companies / Ngrok / Blog / Post Details
Content Deep Dive

Decouple policy from sensitive data: introducing Secrets for Traffic Policy

Blog post from Ngrok

Post Details
Company
Date Published
Author
Brian Melton-Grace
Word Count
456
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

The major upgrade introduced in the developer preview of Secrets for Traffic Policy enhances the security and manageability of sensitive data, such as passwords and API keys, by allowing these values to be stored in secure, encrypted vaults rather than embedded directly in Traffic Policy configurations. This approach eliminates the risk of exposing sensitive information in cleartext, as secrets are dynamically referenced at runtime using macros and are encrypted at rest with AES-256 and in-transit with HTTPS and TLS 1.2. The centralized vault system not only improves security but also streamlines the reuse and rotation of secrets across multiple policies, ensuring consistent updates and reducing errors. However, during the developer preview phase, users should be aware of certain limitations, such as API-only configuration and potential cleartext exposure in Traffic Inspector under full capture mode. Participants in the developer preview have the opportunity to provide feedback and explore new features with early access, helping to shape the future development of this security enhancement.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 27 1,348 137 67 +16%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.