# Secret Store Over Hardcoded Secrets

> Replace an inline secret with a resolved read from a secret store that fails fast when the secret is absent.

Record: `algorithms:no-hardcoded-secrets`
Kind: algorithm
Canonical: https://banes-lab.com/ontology/algorithms#algorithms-no-hardcoded-secrets
Closure: https://banes-lab.com/json/records/algorithms/no-hardcoded-secrets/closure

Listed in [Algorithm contracts](https://banes-lab.com/api/records/algorithms.md), after [Computed Health Over Metric Health](https://banes-lab.com/records/algorithms/no-metrics.md) and before [Boundary Validation Over Unvalidated Input](https://banes-lab.com/records/algorithms/no-unvalidated-input.md).

## Domain

- [Architectural Rules](https://banes-lab.com/records/algorithms-domain/architectural-rules.md)

## Tier

- [leaf](https://banes-lab.com/records/vocabulary/domain-tier-leaf.md)

## Principle

- [Secrets Management](https://banes-lab.com/records/architecture/secrets-management.md)

## Composes

- [Security Core](https://banes-lab.com/records/algorithms/security-core.md)

## Math type

- [Logic](https://banes-lab.com/records/reasoning/math-type-logic.md)

## Linked from

- [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- [Architectural Clusters](https://banes-lab.com/ontology/algorithms/algorithms-domain-architectural-clusters.md)
- [The mathematics](https://banes-lab.com/ontology/reasoning/the-mathematics.md)
- [Domain tiers](https://banes-lab.com/ontology/schema/the-vocabulary-domain-tier.md)
