1:1 mentoring with Big Tech AI engineers
System Design

Config and Secrets

Keep model keys out of images, browsers and logs: validate at boot that a credential resolves, federate pods and CI instead of storing keys, and give each environment its own workspace and limits.

Last updated

Production10 min readFirst readService and Container

After this section you can

  • Validate at boot that a credential resolves, and say why a missing variable is the wrong test
  • Trace a federated token exchange and name the two traps that break it
  • Choose where each credential may live and give each environment its own workspace
27

Config and Secrets

Keep keys out of images, browsers and logs; check credentials at boot.

Key idea

Config says how the service behaves; a secret opens the till. Federate: the pod holds an identity, not a key.

The key stays behind your backend
Browser: no keyYour backend: pod identityModel API

Blue: request. Teal: your backend and its pod identity. Amber: the model. Dashed: the path that must not exist.

Related

More in System Design

Get full access to all 74+ sections with code examples, diagrams, and interactive animations.

Unlock Premium