Where should production secrets live if not in application.yml on GitHub?
PICTURE THIS: HASH MAP
Simple meaning
Use environment variables injected by the orchestrator, or a vault such as HashiCorp Vault or cloud secret manager, mounted at runtime.
WHY — Auth instead of guessing?
Why interviewers care about Auth:
who only read docs from people who shipped.
and tied to Backend work.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens step by step?
Before you speak the answer, walk the interviewer through these steps:
- 1Use environment variables injected
by the orchestrator, or a vault such as HashiCorp Vault or cloud secret manager, mounted at runtime.
- 2Rotate credentials and keep
them out of images and logs.
- 3A leaked DB password
in git history is a production incident, not a style comment.
- 4Give an example
One tiny concrete case you can say aloud.
- 5Common mistake
What juniors usually get wrong.
- 6Close
When you pick this over the alternative.
EXAMPLE — See it in action
Here's a short line you can speak, broken into clear beats:
Note: Adapt this scaffold to your own project — keep it under 60–90 seconds.
Key takeaway
Use environment variables injected by the orchestrator, or a vault such as HashiCorp Vault or cloud secret manager, mounted at runtime. Rotate credentials and keep them out of images and logs.