BAC-L3-OPS-114
Secrets management and key infrastructure
Where a validator's keys live, who can read them, and how you rotate them without stopping the service.
- Level
- L3 — Infrastructure engineer
- Duration
- 3 h
- Maintainer
- DevOps / Blockchain Infrastructure Engineer
Learning objectives
- 01Separate infrastructure secrets from signing keys
- 02Set up secret storage with access auditing
- 03Rotate a secret without downtime
Guided lab
Migrate a deployment's secrets into a vault, with a verifiable access log.
Independent lab
Execute a full secret rotation and demonstrate zero interruption.
Security angle
The whole workshop is a security exercise: threat model, compartmentalisation, revocation, auditability.
Assessment
Executed rotation plus an access log presented at review.
