Multi-CloudHow-To & HardeningRetrospectives

How to Run a Secrets Rotation Fire Drill Across AWS and Azure

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from January 2023, written in 2026 with the benefit of hindsight.

When a provider tells you to rotate everything, the hardest part is knowing what "everything" is. A rotation fire drill — practiced in advance — makes it manageable. Here is how to run one across AWS and Azure.

Step 1: Build the secrets inventory

List secrets by location and type:

  • CI/CD: environment variables, secret stores, service connections (GitHub, GitLab, Azure DevOps, CircleCI, Jenkins).
  • AWS: IAM user access keys, Secrets Manager secrets, Parameter Store SecureStrings.
  • Azure: app registration client secrets and certificates, storage account keys, Key Vault secrets, SAS tokens.
  • Third-party APIs: payment, email, monitoring, SaaS tokens.
  • SSH keys and signing keys.

Record owner, consumers and rotation method for each.

Step 2: Prioritize

Rank by blast radius: cloud admin credentials first, then production data access, then everything else.

Step 3: Define rotation procedures

For each secret type, document how to rotate without downtime (for example, dual keys for storage accounts and Cosmos DB, overlapping app registration secrets, Secrets Manager rotation functions).

Step 4: Run the drill

Pick a scenario ("our CI/CD provider was breached") and rotate a representative subset — in production, where safe. Time each step.

Step 5: Fix what slowed you down

Typical findings: unknown consumers, hardcoded secrets, manual steps, missing owners. Fix them.

Step 6: Reduce the inventory

Replace secrets with identity: OIDC federation for CI/CD, managed identities in Azure, IAM roles in AWS.

Repeat

Twice a year. Track time to rotate all critical secrets.

secrets rotation processCircleCI2023

More on this story