Reference
CyberArk Conjur
Sync an environment with the variables in one Conjur policy branch, in either direction.
Sync an environment with the variables in one Conjur policy branch, in either direction.
Connection
| What | This provider |
|---|---|
| Vendor | CyberArk Conjur |
| Key | conjur-variables |
| Availability | available. You can connect it today. |
| Credential we hold | conjur-api-key |
| Values read back | yes |
| Activation | immediate |
Directions
| Direction | What it does |
|---|---|
import | We read names and values out of the store into your environment. |
export | We write names and values from your environment into the store. |
Activation
immediate. The running app sees a new value at once.
Conflict policies
| Direction | Policies you can pick |
|---|---|
import | skip_existing, new_version, fail |
export | create_only, overwrite, overwrite_and_prune |
How syncs work says what each one does.
Connect
Paste a credential from the vendor. We seal it and never show it again.
| Field | Label | Kind | Required | What it is |
|---|---|---|---|---|
login | Host login | text | yes | The workload's full login. On Secrets Manager, SaaS it starts with host/data/. |
apiKey | API key | secret; we mask it here and seal it | yes | The host's API key, from the policy load that created it or from rotating it. We exchange it for a token on every run and never store the token. |
Connection fields
You set these when you connect. Every mapping on the connection shares them.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
url | Conjur URL | text | yes | no | For Secrets Manager, SaaS: your tenant subdomain followed by /api. For a self-hosted Conjur: its appliance URL. It must be reachable from the internet. |
account | Account | text | yes | yes | conjur on Secrets Manager, SaaS. On a self-hosted Conjur, the account it was set up with. Starts at conjur. |
Mapping fields
You answer these once per environment you map.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
branch | Policy branch | text | yes | no | We read and write the variables directly in this branch, whichever policy declared them. Export declares new ones here. Pruning deletes every variable here that this environment lacks, including ones this sync never wrote, and stops if one of them was declared by a parent policy. |
Required permissions
We probe for these when we verify the connection.
| Permission | Directions | Blocking | Without it |
|---|---|---|---|
authenticate | every direction | yes | The host cannot log in, so nothing can be read or written. |
read | every direction | yes | Preview cannot see the branch's variables. |
execute | import | yes | Import cannot fetch a value. |
update | export | yes | Export cannot set a value, or delete a variable when pruning. |
create | export | yes | Export cannot declare a variable the branch does not have yet. |