Ask HN: Strategy for handling user-managed 3rd party secrets for SaaS App?
This is mainly in context of a multi-tenant SaaS app. I realize providing secrets to a 3rd party causes most people to shudder, but this could apply to a dedicated or on-premises version of our app, where users still have the ability to manage custom connections via the UI.
This is different than managing the secrets for our own internal infrastructure.
The scenario when this issue comes up is when you provide users the ability (via a frontend UI etc) to manage:
1. Custom API Connections
2. Custom Database connections
3. Managing custom hosting/server settings
Example use case:
User uses our app to view data from a database they own and manage.
1. An admin type user adds connection info/credentials via a settings page in our app.
2. We store those settings permanently.
3. The admin (using our UI) adds authorization rules for other users in our app (within their tenant/company).
4. These users access our app to view data from their db.
5. Our backend service receives the request, retrieves/caches their tenant db settings, connects to their db, retrieves data.
Although this case is for a database, it could be for a GraphQL/REST Api service also.
The Issue:
Everyone know's not to store passwords in plain text, but these are basically passwords. The difference is that our backend needs to be able to read and use them. They need to be managed and stored in a scalable way since they are managed by the end-user.
We have a few strategies in mind but are looking for the most current recommendations.
Most of our infrastructure is using Kubernetes and Compute Engine on Google Cloud.
edit: formatting