{"product_id":"nikodem-secrets-management-workload-identity","title":"Nikodem — Secrets Management \u0026 Workload Identity Engineer AI Skill","description":"\u003cdiv style=\"font-family: 'DM Sans', sans-serif; color: #1A1A18; max-width: 680px;\"\u003e\n  \u003cp style=\"font-size: 16px; font-weight: 600; line-height: 1.5; margin: 0 0 8px 0;\"\u003eDrop Nikodem into Claude and get a secrets engineer whose goal is that the credential you are trying to protect stops existing.\u003c\/p\u003e\n  \u003cp style=\"font-size: 13px; color: #555550; line-height: 1.7; margin: 0 0 28px 0;\"\u003eNikodem owns machine identity and the secrets that should not be there: secret sprawl discovery across repositories, CI logs, container images, config maps, wikis and ticketing systems, scanning in pre-commit and CI with the false-positive problem handled, centralised secret stores including HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager and CyberArk with auth methods, policy design and dynamic short-lived credentials, workload identity federation and OIDC-based keyless authentication so CI never holds a static cloud key, SPIFFE and SPIRE, Kubernetes service accounts, IRSA and pod identity, mTLS and service mesh identity, rotation that actually happens including the credential three systems hardcode, break-glass credential storage, database and third-party credential brokering, the difference between encrypting a secret and controlling access to it, and the post-leak playbook of rotate, invalidate, hunt for use and purge history.\u003c\/p\u003e\n  \u003cdiv style=\"background: #fbeff3; border-radius: 12px; padding: 24px 28px; margin-bottom: 24px;\"\u003e\n    \u003cp style=\"font-size: 10px; font-weight: 600; color: #d3225d; letter-spacing: 0.08em; text-transform: uppercase; margin: 0 0 16px 0;\"\u003eWhat you get\u003c\/p\u003e\n    \u003cul style=\"margin: 0; padding: 0; list-style: none;\"\u003e\n\u003cli style=\"font-size: 13px; padding: 7px 0; border-bottom: 1px solid rgba(211,34,93,0.14); display: flex; gap: 10px;\"\u003e\n\u003cspan style=\"color:#d3225d; font-weight:600;\"\u003e→\u003c\/span\u003e\u003cspan\u003eSecret sprawl discovery and CI scanning with tuned signal\u003c\/span\u003e\n\u003c\/li\u003e\n\u003cli style=\"font-size: 13px; padding: 7px 0; border-bottom: 1px solid rgba(211,34,93,0.14); display: flex; gap: 10px;\"\u003e\n\u003cspan style=\"color:#d3225d; font-weight:600;\"\u003e→\u003c\/span\u003e\u003cspan\u003eVault and cloud secret store policy and dynamic credentials\u003c\/span\u003e\n\u003c\/li\u003e\n\u003cli style=\"font-size: 13px; padding: 7px 0; border-bottom: 1px solid rgba(211,34,93,0.14); display: flex; gap: 10px;\"\u003e\n\u003cspan style=\"color:#d3225d; font-weight:600;\"\u003e→\u003c\/span\u003e\u003cspan\u003eWorkload identity federation, OIDC keyless CI, SPIFFE and IRSA\u003c\/span\u003e\n\u003c\/li\u003e\n\u003cli style=\"font-size: 13px; padding: 7px 0;  display: flex; gap: 10px;\"\u003e\n\u003cspan style=\"color:#d3225d; font-weight:600;\"\u003e→\u003c\/span\u003e\u003cspan\u003eRotation, break-glass and the post-leak rotate-and-hunt playbook\u003c\/span\u003e\n\u003c\/li\u003e\n    \u003c\/ul\u003e\n  \u003c\/div\u003e\n  \u003cdiv style=\"display:flex; align-items:center; gap:20px; background:#FFFFFF; border:1px solid #E8E6E0; border-radius:8px; padding:14px 20px; margin-bottom:24px;\"\u003e\n    \u003cspan style=\"font-size:11px; color:#888780; font-family:monospace;\"\u003e📄 nikodem-secrets-management-workload-identity.skill\u003c\/span\u003e\n    \u003cspan style=\"font-size:11px; color:#888780;\"\u003eUnder 2 min install\u003c\/span\u003e\n    \u003cspan style=\"font-size:11px; color:#888780;\"\u003eWorks with Claude, ChatGPT \u0026amp; any AI chat\u003c\/span\u003e\n  \u003c\/div\u003e\n  \u003cdiv style=\"border-left:3px solid #d3225d; padding-left:16px;\"\u003e\n    \u003cp style=\"font-size:10px; font-weight:600; color:#d3225d; letter-spacing:0.08em; text-transform:uppercase; margin:0 0 6px 0;\"\u003eHow to install\u003c\/p\u003e\n    \u003cp style=\"font-size:12px; color:#555550; line-height:1.7; margin:0;\"\u003eDownload the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Nikodem builds the answer. Includes a full worked example so you see exactly what you get.\u003c\/p\u003e\n  \u003c\/div\u003e\n\u003c\/div\u003e","brand":"KissMySkills","offers":[{"title":"Default Title","offer_id":58390448341256,"sku":null,"price":14.99,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1036\/1444\/7880\/files\/3444702f-eb7b-4afc-917b-460aaf4459e1.png?v=1786112798","url":"https:\/\/kissmyskills.com\/it\/products\/nikodem-secrets-management-workload-identity","provider":"KissMySkills","version":"1.0","type":"link"}