Secret Sprawl
Kind: anti-pattern
Layer: Enforcement Core
Record: architecture:secret-sprawl
Severity: discouraged
Scope: modularity, security_governance
Formed by: Store credentials, tokens, keys, certificates, or sensitive configuration across code, config files, logs, tickets, and local environments.
Canonical: Ontology
A defect in which credentials and keys are stored across code, logs and configuration.
Listed in Architecture principles, after Authorization Scattering and before Personal Data Oversharing.