Spent real time with HashiCorp Vault this year — dynamic secrets, KV engines, CI pipelines pulling credentials at runtime instead of storing them anywhere static.
Biggest shift in how I think about secrets: the goal isn't "encrypt it," it's "make sure it never has to live anywhere long enough to leak."