Skip to content

OVES Secrets & Trust Infrastructure

Documentation for OVES secret management strategy, trust infrastructure roadmap, and architecture decisions.

Principles

  1. Human credentials and machine secrets are separate concerns — different tools, different governance
  2. Vault OSS is the strategic platform — deploy as Vault-Lite initially, expand as maturity grows
  3. Bitwarden is the system of record for human credentials — standardize before expanding machine trust
  4. Delay complexity, not platform choice — the right platform from day one, operated at the right level

Four Layers

Layer Question Tool
Identity Who are you? Azure AD, Passkeys
Secret Management What may be accessed? Vault OSS
Trust Infrastructure How do systems prove identity? Vault PKI
Blockchain Anchoring How can trust become immutable? Public blockchain

Small notes: progressive architecture decisions are tracked in Architecture Decision Records; stable lookup material lives under Reference.