What is secret management?
Secret management keeps passwords, API keys, and tokens out of the repository.

What it is
Secrets are values that do not belong in Git: database passwords, API keys, tokens for the pipeline, keys for other people’s services. If they sit in the repository, they stay in the history even after you delete them from the latest file. Anyone who can read the repo can read them. A public repository makes them readable worldwide.
A value in the repository stays in the history, even after you delete it from the latest file.
What it is made of
Secret management is the place outside the code, and the way to hand the values to the running app. The app sees the value at runtime as an environment variable or through a fetch. It is not in the image and not in the Git log.
What goes wrong
Who may change the value, and who may only use it, belongs to that. A token that was in a chat is burned, even if you delete the message. You create a new one and revoke the old one. Without a place where the current value lives, you do not know which copy still counts.
What you otherwise look after yourself
Different environments have different secrets. Dev does not talk to the production database. If both sit in the same file, the split is already gone.
How it shows up on MainPath
On MainPath those are the project’s environment variables, not a .env you commit. The pipeline and the running service receive them. The repository does not.