Kestra offers integration with secret managers. Secrets will be stored directly on a secret back-end and workers will read them at runtime only (in memory only).

Secrets can be set using the user interface or via Terraform.

For now, we provide integration only using Vault or Elasticsearch, but other options will be added in the future.