Reference
Alibaba Cloud Secrets Manager
Move secrets to and from Alibaba Cloud KMS Secrets Manager in one region.
Move secrets to and from Alibaba Cloud KMS Secrets Manager in one region.
Connection
| What | This provider |
|---|---|
| Vendor | Alibaba Cloud |
| Key | alibaba-kms-secrets |
| Availability | available. You can connect it today. |
| Credential we hold | alibaba-access-key |
| Values read back | yes |
| Activation | immediate |
Directions
| Direction | What it does |
|---|---|
import | We read names and values out of the store into your environment. |
export | We write names and values from your environment into the store. |
Activation
immediate. The running app sees a new value at once.
Conflict policies
| Direction | Policies you can pick |
|---|---|
import | skip_existing, new_version, fail |
export | create_only, overwrite, overwrite_and_prune |
How syncs work says what each one does.
Connect
Paste a credential from the vendor. We seal it and never show it again.
| Field | Label | Kind | Required | What it is |
|---|---|---|---|---|
accessKeyId | AccessKey ID | text | yes | In the RAM console, open Users, pick a user, then Create AccessKey. |
accessKeySecret | AccessKey secret | secret; we mask it here and seal it | yes | Shown once, beside the ID, when you create the key. |
Connection fields
You set these when you connect. Every mapping on the connection shares them.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
region | Region | text | yes | no | The region that holds the secrets. One connection covers one region. |
kmsInstanceId | KMS instance ID | text | no | yes | Set it if your account creates secrets in a KMS instance. Find it under KMS, then Instances. |
Mapping fields
You answer these once per environment you map.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
namePrefix | Secret name prefix | text | yes | no | We name each secret prefix/KEY and only touch generic secrets under this prefix. |
Required permissions
We probe for these when we verify the connection.
| Permission | Directions | Blocking | Without it |
|---|---|---|---|
kms:ListSecrets | every direction | yes | Preview cannot list the secrets under this prefix. |
kms:GetSecretValue | every direction | yes | Import cannot read values, and export cannot tell which values changed. |
kms:CreateSecret | export | yes | Export cannot create a new secret. |
kms:PutSecretValue | export | yes | Export cannot change a value that is already there. |
kms:DeleteSecret | export | no | The overwrite_and_prune policy cannot remove secrets. |
kms:RestoreSecret | export | no | Export cannot write to a name you pruned until its 30-day window ends. |