10 parts · 14 chapters
Configuration, Secrets and Feature Flags
Configuration starts as a few environment variables and ends as one of the most dangerous systems a company runs: config changes cause a large share of outages, and leaked secrets cause a large share of breaches. This course follows configuration and secrets from a .env file to Vault with dynamic credentials, and feature flags from an if statement to a targeting platform.
Ten parts: the twelve-factor baseline and where it stops working; configuration layers; HashiCorp Vault; cloud secret managers and Kubernetes integrations; Consul and etcd; rotating secrets without downtime; feature flags; configuration as code with validation and review; config incidents; and a capstone that rotates a database password under load with zero errors.
layersDefaults, environment, files, remote config, per-tenant config, and precedence.
VaultSecrets engines, dynamic database credentials, leases, PKI, auth methods, policies.
KubernetesSecrets, External Secrets Operator, Sealed Secrets, SOPS, CSI drivers.
rotationDual credentials, overlap windows, and rotation without downtime.
flagsTargeting, percentage rollouts, kill switches, OpenFeature, flag debt.
safetySchemas, review, canaries and rollback for configuration changes.
00
The Twelve-Factor Baseline and Its Limits
Config in the environment, and where it breaks · Configuration layers and precedence
2 ch · ~12 min01Configuration Layers
How each runtime loads configuration
1 ch · ~8 min02HashiCorp Vault
Architecture, engines and auth methods · Dynamic credentials, leases and the agent
2 ch · ~12 min03Cloud Secret Managers and Kubernetes
Managers, KMS and envelope encryption · Getting secrets into pods
2 ch · ~12 min04Consul and etcd as Configuration Stores
Consul KV, etcd and watches
1 ch · ~8 min05Secret Rotation Without Downtime
The overlap pattern, by secret type
1 ch · ~8 min06Feature Flags
Kinds of flags and how they are evaluated · OpenFeature, testing and flag debt
2 ch · ~12 min07Configuration as Code, Validation and Review
Config changes are deploys
1 ch · ~8 min08Config Incidents and How to Prevent Them
Six incident shapes
1 ch · ~8 min09Capstone: Rotate a Database Password Under Load
The exercise
1 ch · ~8 minBuilt on Infra and the Production StackAssumes Infrastructure part 3 (environments, GitOps and secrets basics) and the Production Stack course; Deployment Techniques and Service Mesh follow.