What is STACKIT Secrets Manager?
STACKIT Secrets Manager is a fully managed service that provides a secure key-value store for sensitive data such as passwords, API keys, certificates, and configuration parameters. The service enables separation of secrets from source code in line with common security requirements. STACKIT operates the service exclusively in German data centers for complete GDPR compliance.
Core Features
- Centralized, encrypted key-value store for secrets, separate from source code
- Versioning of secrets for traceability and rollback
- API modeled on the HashiCorp Vault KV2 interface
- Integration with tools such as Terraform
- KMS integration for encrypting stored secrets
- Managed high-availability infrastructure with automatic updates
Typical Use Cases
Database Credentials for Microservices: Instead of storing passwords in environment variables, credentials are retrieved from Secrets Manager at runtime.
API Keys for External Services: Payment providers, email services, and cloud APIs require API keys. Secrets Manager stores these encrypted and versioned for quick rollback.
Centralized Configuration Management: Application configurations and credentials are managed centrally and distributed across environments (dev, staging, production) via the API.
Benefits
- Complete data sovereignty in German data centers
- Versioning for quick rollback in case of faulty changes
- Compatibility with existing Vault-based workflows through a KV2-compatible API
- GDPR compliant with an audit trail
Integration with innFactory
As an official STACKIT partner, innFactory supports you with STACKIT Secrets Manager: architecture, migration, operations, and cost optimization.
Available Tiers & Options
Standard
- Tiered capacity levels
- Versioning
- Vault KV2-compatible API
- Capacity bound to the booked tier
Typical Use Cases
Frequently Asked Questions
What is STACKIT Secrets Manager?
STACKIT Secrets Manager is a managed key-value store for protecting and managing sensitive data such as passwords, API keys, and configuration files, kept separate from source code.
How are secrets encrypted?
Secrets are stored encrypted server-side, with encryption configurable via a KMS integration. Configuration details are documented in the current STACKIT documentation.
Is the API compatible with HashiCorp Vault?
The Secrets Manager API is modeled on the HashiCorp Vault KV2 API, allowing existing Vault CLI workflows and tools to be reused with adjustments.
How do applications access secrets?
Access happens via an API as well as integrations with common tools such as Terraform. For production use, check the current integration documentation for your target system.
Is STACKIT Secrets Manager GDPR compliant?
Yes, the service operates exclusively in German data centers. STACKIT provides data processing agreements and is ISO 27001 certified.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.
