Penv Cloud
Start free
Docs
Reference

Alibaba Cloud Secrets Manager

Move secrets to and from Alibaba Cloud KMS Secrets Manager in one region.

Move secrets to and from Alibaba Cloud KMS Secrets Manager in one region.

Connection

WhatThis provider
VendorAlibaba Cloud
Keyalibaba-kms-secrets
Availabilityavailable. You can connect it today.
Credential we holdalibaba-access-key
Values read backyes
Activationimmediate

Directions

DirectionWhat it does
importWe read names and values out of the store into your environment.
exportWe write names and values from your environment into the store.

Activation

immediate. The running app sees a new value at once.

Conflict policies

DirectionPolicies you can pick
importskip_existing, new_version, fail
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

Connect

Paste a credential from the vendor. We seal it and never show it again.

FieldLabelKindRequiredWhat it is
accessKeyIdAccessKey IDtextyesIn the RAM console, open Users, pick a user, then Create AccessKey.
accessKeySecretAccessKey secretsecret; we mask it here and seal ityesShown once, beside the ID, when you create the key.

Connection fields

You set these when you connect. Every mapping on the connection shares them.

FieldLabelKindRequiredAdvancedWhat it is
regionRegiontextyesnoThe region that holds the secrets. One connection covers one region.
kmsInstanceIdKMS instance IDtextnoyesSet it if your account creates secrets in a KMS instance. Find it under KMS, then Instances.

Mapping fields

You answer these once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
namePrefixSecret name prefixtextyesnoWe name each secret prefix/KEY and only touch generic secrets under this prefix.

Required permissions

We probe for these when we verify the connection.

PermissionDirectionsBlockingWithout it
kms:ListSecretsevery directionyesPreview cannot list the secrets under this prefix.
kms:GetSecretValueevery directionyesImport cannot read values, and export cannot tell which values changed.
kms:CreateSecretexportyesExport cannot create a new secret.
kms:PutSecretValueexportyesExport cannot change a value that is already there.
kms:DeleteSecretexportnoThe overwrite_and_prune policy cannot remove secrets.
kms:RestoreSecretexportnoExport cannot write to a name you pruned until its 30-day window ends.