Deactivation
Deactivation recommends removing or disabling a secret that is unused or has never been used within a 60-day period, based on upstream provider logs.
Supported Integrations
The following integrations support secret deactivation:
When is this recommended?
Ledger recommends deactivation for a long-lived secret when usage logs in the upstream platform show that it has not been used within a 60-day period.
Ledger also does not recommend any cleanup actions for workloads that have the unused secret in their configuration.
What does the workflow look like?
Ledger walks you through the following steps, providing detailed guidance based on the target upstream provider:
- Review the target secret and usage information.
- Remove or disable the secret in the upstream provider.
Ledger automatically closes the remediation workflow when the secret is deactivated, but you may need to re-run an integration scan to refresh the inventory for latest secret status.
Outcome
The secret is disabled or deleted in the upstream provider, and is no longer an available attack vector.