--- title: "Secrets" canonical: "https://admiral.io/docs/security/secrets" description: "Admiral stores a pointer into your secret manager and the agent resolves it, while chart values pass through exactly as you wrote them." --- # Secrets Admiral works with the way you already handle secrets. A team that already reads secrets from its own module, or that already ships Sealed Secrets, External Secrets, or a Vault chart, keeps doing that. ## How do I keep a secret out of Admiral? [#how-do-i-keep-a-secret-out-of-admiral] For a Terraform component, a value may name an entry in GCP Secret Manager, AWS Secrets Manager, or Vault. The reference is one string, `secret(":
")`, and the address is the manager's own identifier: ```yaml db_password: ref: secret("gcp:projects/acme-prod/secrets/users-db-password") api_token: ref: secret("aws:arn:aws:secretsmanager:us-east-1:111122223333:secret:api-token#token") tls_key: ref: secret("vault:kv/data/users-db#tls_key") ``` * `#key` reads one field of a JSON or key/value secret. Vault needs it. On AWS, leaving it off reads the whole secret string. * A reference reads the latest version unless you pin one, with `/versions/N` on GCP or `?version=` on AWS. An unpinned reference is read at apply, so a rotated secret needs no changeset. Admiral stores that pointer. When you plan, Admiral renders each component into a **run artifact**, the exact files the agent receives, and the pointer goes into it unresolved. The agent resolves it with the cloud identity it already uses to apply. The control plane does not. ```mermaid flowchart LR Ref["Value
secret("gcp:…")"] --> CP["Control plane
stores the pointer"] CP --> Agent["Agent
resolves at apply"] Agent --> SM["Your manager
GCP, AWS, or Vault"] ``` The reference is offered. It is not required. A module may keep using a data source. ## What happens to secrets in chart values? [#what-happens-to-secrets-in-chart-values] A workload gets no secret resolution from Admiral. A chart's values are what the chart takes. Sealed Secrets ciphertext, an ExternalSecret name, a Vault wrapper, or plaintext you chose to put there all pass through untouched. Admiral does not refuse a chart and does not rewrite one. Plaintext you put in values is stored as you gave it. ## Which secrets still land in Terraform state? [#which-secrets-still-land-in-terraform-state] A secret fed to an ordinary Terraform input lands in [state](https://admiral.io/docs/concepts/state.md). An ephemeral input or a write-only argument stays out of it. The changeset review shows which kind each secret input is. When Admiral hosts the state, it encrypts it the way it encrypts a stored credential, and Admiral can decrypt it. When a component keeps its own backend, the secret lands in that backend, and Admiral never holds it. Admiral has no secret store of its own, so a reference always points into your own manager. ## Where to go next [#where-to-go-next] * [State](https://admiral.io/docs/concepts/state.md): Where an ordinary Terraform input is stored after apply * [Credentials](https://admiral.io/docs/concepts/sources-and-catalog.md#credentials): A different secret: what a private pull may present