Task: Elaborate on secret management and external project dependencies

Elaborate on secret management and external project dependencies

Investigate how to handle secrets, credentials, and external services to keep the project secure and reproducible.

The Problem

A significant part of the production system resides outside of Git: credentials, API keys, OAuth applications, DNS, email, payments, object storage, external databases, and other services. Without understanding these dependencies, it is impossible to fully restore the project or safely transfer it to another owner.

At the same time, secrets themselves cannot be turned into regular project data or copied mindlessly between environments.

Direction

We need to explore a model where the infrastructure is aware of the existence and purpose of external dependencies, knows how to check their availability, and understands what credentials a specific environment needs without disrupting existing secret management mechanisms.

We do not assume building a custom secret store in advance: it is important to define requirements and boundaries of responsibility.

Related to environments, project state, and portability.