10 parts · 14 chapters

Configuration, Secrets and Feature Flags

Configuration starts as a few environment variables and ends as one of the most dangerous systems a company runs: config changes cause a large share of outages, and leaked secrets cause a large share of breaches. This course follows configuration and secrets from a .env file to Vault with dynamic credentials, and feature flags from an if statement to a targeting platform.

Ten parts: the twelve-factor baseline and where it stops working; configuration layers; HashiCorp Vault; cloud secret managers and Kubernetes integrations; Consul and etcd; rotating secrets without downtime; feature flags; configuration as code with validation and review; config incidents; and a capstone that rotates a database password under load with zero errors.

twelve-factor and its limits · config layers · Vault · cloud secrets and Kubernetes · Consul and etcd · rotation · feature flags · config as code · config incidents · capstonesenior → staff · backend, platform and security-minded engineers
layersDefaults, environment, files, remote config, per-tenant config, and precedence.
VaultSecrets engines, dynamic database credentials, leases, PKI, auth methods, policies.
KubernetesSecrets, External Secrets Operator, Sealed Secrets, SOPS, CSI drivers.
rotationDual credentials, overlap windows, and rotation without downtime.
flagsTargeting, percentage rollouts, kill switches, OpenFeature, flag debt.
safetySchemas, review, canaries and rollback for configuration changes.
Built on Infra and the Production StackAssumes Infrastructure part 3 (environments, GitOps and secrets basics) and the Production Stack course; Deployment Techniques and Service Mesh follow.