# Secret Has Excessive Keys | ZopNight

> Many credentials share one object, so anything granted access to it gets all of them and rotating one means touching every consumer.

Source: https://zop.dev/zopnight/rules/secret-has-excessive-keys

---

_Governance · Low severity_

## Secret Has Excessive Keys

Many credentials share one object, so anything granted access to it gets all of them and rotating one means touching every consumer.

- 3 — clouds covered
- Low — severity
- Compliance — where it shows up
- Manual — fix, change spelled out

Free to start. No card. The playground just needs your work email.

## Found, explained, handed over.

Where the estate departs from your policies, frameworks and tagging rules.

- 01. Detect — ZopNight checks this automatically across AWS, Azure and Google Cloud, with read-only access to the account.
- 02. Explain — Every finding says exactly what to change: Split the oversized secret.
- 03. Fix — The finding opens with the change already spelled out, so the fix is one ticket, not an investigation.

- applies_to_fallback: Any resource in the account
- where_it_appears: The Compliance tab of Recommendations, with every affected resource listed.

## Related

- [Legacy Service-Account-Token Secret](https://zop.dev/zopnight/rules/legacy-service-account-token-secret)
- [ResourceQuota Exhausted](https://zop.dev/zopnight/rules/resourcequota-exhausted)
- [CronJob Never Scheduled](https://zop.dev/zopnight/rules/cronjob-never-scheduled)
- [ResourceQuota Near Limit](https://zop.dev/zopnight/rules/resourcequota-near-limit)
- [Snowflake Large Cold Table](https://zop.dev/zopnight/rules/snowflake-large-cold-table)
- [Snowflake Steady Baseline, Consider Capacity Pricing](https://zop.dev/zopnight/rules/snowflake-steady-baseline-consider-capacity-pricing)

## See the governance findings in your account.

Connect a read-only role and the first pass runs on your own estate. This check, and the rest of the catalogue, with it.

[object Object]
