Security and Access

The wiki should describe how to obtain or rotate access, never store the secret itself.

Never commit

Do not place these in wiki Markdown, attachments or repository history:

  • passwords;
  • API tokens and personal access tokens;
  • OAuth/OIDC client secrets;
  • private keys or recovery codes;
  • database connection strings containing credentials;
  • session cookies;
  • private customer or employee data that does not belong in the documentation repository.

Document instead

Record the system name, purpose of the credential, where it is managed, who/which role is expected to have access, rotation expectations, and the recovery/escalation procedure.

Least privilege

Service and human access should be scoped to the minimum permissions required. Administrative credentials should not be reused as application credentials.

Incident handling

If a secret is accidentally committed, deleting the page is insufficient because Git history may retain it. Rotate/revoke the secret first, then remove it from current content and rewrite repository history only when appropriate. Record the event using Templates/Incident-Review without reproducing the exposed secret.

0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9