Secrets Management

Never commit or log secret values. .env.example contains names and non-secret defaults only. Kubernetes uses External Secrets Operator to copy properties from a configured SecretStore/Vault remote key into a Kubernetes Secret.

Sensitive values include Slack bot/app tokens and signing secret; OpenAI/Galileo keys; GitHub App private key, OAuth client secret, and legacy token; TOKEN_ENCRYPTION_KEY; Jira token, email, and Cloudflare Access secret; MuleSoft credentials; and user PAT/OAuth tokens.

Use SLACK_ALLOW_UNSIGNED_REQUESTS=false. Rotate a compromised credential at its issuer and update the external secret. Rotating TOKEN_ENCRYPTION_KEY without migrating ciphertext makes stored GitHub and Confluence tokens unreadable. Exact Vault access policy, rotation cadence, and break-glass process are TO_BE_CONFIRMED.

Before model generation, the application redacts patterns for Slack tokens, GitHub tokens, OpenAI-style keys, and AWS access-key IDs. This is a limited pattern set, not a substitute for users removing confidential material. Audit events exclude Slack message bodies and credentials.