Penv Cloud
Start free
Docs
Reference

CyberArk Conjur

Sync an environment with the variables in one Conjur policy branch, in either direction.

Sync an environment with the variables in one Conjur policy branch, in either direction.

Connection

WhatThis provider
VendorCyberArk Conjur
Keyconjur-variables
Availabilityavailable. You can connect it today.
Credential we holdconjur-api-key
Values read backyes
Activationimmediate

Directions

DirectionWhat it does
importWe read names and values out of the store into your environment.
exportWe write names and values from your environment into the store.

Activation

immediate. The running app sees a new value at once.

Conflict policies

DirectionPolicies you can pick
importskip_existing, new_version, fail
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

Connect

Paste a credential from the vendor. We seal it and never show it again.

FieldLabelKindRequiredWhat it is
loginHost logintextyesThe workload's full login. On Secrets Manager, SaaS it starts with host/data/.
apiKeyAPI keysecret; we mask it here and seal ityesThe host's API key, from the policy load that created it or from rotating it. We exchange it for a token on every run and never store the token.

Connection fields

You set these when you connect. Every mapping on the connection shares them.

FieldLabelKindRequiredAdvancedWhat it is
urlConjur URLtextyesnoFor Secrets Manager, SaaS: your tenant subdomain followed by /api. For a self-hosted Conjur: its appliance URL. It must be reachable from the internet.
accountAccounttextyesyesconjur on Secrets Manager, SaaS. On a self-hosted Conjur, the account it was set up with. Starts at conjur.

Mapping fields

You answer these once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
branchPolicy branchtextyesnoWe read and write the variables directly in this branch, whichever policy declared them. Export declares new ones here. Pruning deletes every variable here that this environment lacks, including ones this sync never wrote, and stops if one of them was declared by a parent policy.

Required permissions

We probe for these when we verify the connection.

PermissionDirectionsBlockingWithout it
authenticateevery directionyesThe host cannot log in, so nothing can be read or written.
readevery directionyesPreview cannot see the branch's variables.
executeimportyesImport cannot fetch a value.
updateexportyesExport cannot set a value, or delete a variable when pruning.
createexportyesExport cannot declare a variable the branch does not have yet.