Managing "Secret" Injection in DABs across Dev/Stage/Prod

Khasim_1
New Contributor III

Hi everyone, I am fully moving our team to Databricks Asset Bundles (DABs) for CI/CD, but I’m struggling with the "Secret" management pattern.

  1. How are you handling the injection of secrets (like API keys for ingestion) into DABs without hardcoding anything in the databricks.yml?
  2. Do you use Databricks Secret Scopes referenced via environment variables in the bundle, or are you pulling them dynamically from an external vault (e.g., KeyVault/Secrets Manager) during the deploy phase?
  3. What is the cleanest way to maintain "Environment Parity" for these secrets without having to manually configure scopes in each workspace?
Data Architect | 13 Years Domain Expertise | Databricks SA Champion Cohort