How to Run a Secrets Rotation Fire Drill Across AWS and Azure
Retrospective: this article looks back at events from January 2023, written in 2026 with the benefit of hindsight.
When a provider tells you to rotate everything, the hardest part is knowing what "everything" is. A rotation fire drill — practiced in advance — makes it manageable. Here is how to run one across AWS and Azure.
Step 1: Build the secrets inventory
List secrets by location and type:
- CI/CD: environment variables, secret stores, service connections (GitHub, GitLab, Azure DevOps, CircleCI, Jenkins).
- AWS: IAM user access keys, Secrets Manager secrets, Parameter Store SecureStrings.
- Azure: app registration client secrets and certificates, storage account keys, Key Vault secrets, SAS tokens.
- Third-party APIs: payment, email, monitoring, SaaS tokens.
- SSH keys and signing keys.
Record owner, consumers and rotation method for each.
Step 2: Prioritize
Rank by blast radius: cloud admin credentials first, then production data access, then everything else.
Step 3: Define rotation procedures
For each secret type, document how to rotate without downtime (for example, dual keys for storage accounts and Cosmos DB, overlapping app registration secrets, Secrets Manager rotation functions).
Step 4: Run the drill
Pick a scenario ("our CI/CD provider was breached") and rotate a representative subset — in production, where safe. Time each step.
Step 5: Fix what slowed you down
Typical findings: unknown consumers, hardcoded secrets, manual steps, missing owners. Fix them.
Step 6: Reduce the inventory
Replace secrets with identity: OIDC federation for CI/CD, managed identities in Azure, IAM roles in AWS.
Repeat
Twice a year. Track time to rotate all critical secrets.
- CircleCI Secrets Breach (Jan 2023): Rotate Everything Incident Teardowns
- Detecting CI/CD Secrets Theft: Sentinel and GuardDuty Detections Detection & Response
- CIO Brief: When a Dev Tool Breach Forces a Company-Wide Credential Reset CIO Briefings