POLICY-DRIVEN SECRETS MANAGEMENT FOR SECURE API DEVELOPMENT AND DEPLOYMENT
Abstract
Secure management of application secrets has become a fundamental requirement for cloudnative API development because exposed credentials, API keys, certificates, and encryption tokens represent major attack vectors within distributed enterprise environments. Conventional secrets management approaches frequently rely on hardcoded credentials, manual configuration, and inconsistent access controls, increasing security risks and operational complexity. This paper proposes a policy-driven secrets management framework integrating centralized secrets management, OpenAPI Specification, DevSecOps, cloud-native deployment, machine learning-assisted governance, automated compliance validation, and enterprise security policies for secure API development and deployment. The proposed methodology enforces policy-based secret provisioning, dynamic credential rotation, finegrained access control, runtime validation, continuous monitoring, and automated compliance throughout the API lifecycle. Experimental evaluation demonstrates improvements in credential protection, governance efficiency, deployment reliability, compliance management, and enterprise security. The proposed framework provides a productionready solution for secure secrets management within modern API engineering and cloud-native enterprise applications. Keywords— Secrets Management, API Security, DevSecOps, OpenAPI Specification, CloudNative Security, Enterprise Governance, Credential Management, Policy-Based Security.