Penv Cloud
Start free
Docs
Reference

IBM Cloud Secrets Manager

Sync an environment with the arbitrary secrets in one Secrets Manager secret group.

Sync an environment with the arbitrary secrets in one Secrets Manager secret group.

Connection

WhatThis provider
VendorIBM Cloud
Keyibm-secrets-manager
Availabilityavailable. You can connect it today.
Credential we holdibm-iam-key
Values read backyes
Activationimmediate

Directions

DirectionWhat it does
importWe read names and values out of the store into your environment.
exportWe write names and values from your environment into the store.

Activation

immediate. The running app sees a new value at once.

Conflict policies

DirectionPolicies you can pick
importskip_existing, new_version, fail
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

Connect

Paste a credential from the vendor. We seal it and never show it again.

FieldLabelKindRequiredWhat it is
apiKeyAPI keysecret; we mask it here and seal ityesCreate one under Manage, Access (IAM), then API keys, for a service ID with a role on this instance. We exchange it for a one-hour token on every run and never store the token.

Connection fields

You set these when you connect. Every mapping on the connection shares them.

FieldLabelKindRequiredAdvancedWhat it is
instanceIdInstance IDtextyesnoIn the Secrets Manager instance, open Endpoints. The ID is the first part of the public endpoint's host.
regionRegionchoiceyesyesThe region in the instance's public endpoint. One of Dallas (us-south), Washington DC (us-east), Toronto (ca-tor), Montreal (ca-mon), Sao Paulo (br-sao), London (eu-gb), Frankfurt (eu-de), Madrid (eu-es), Tokyo (jp-tok), Osaka (jp-osa), Sydney (au-syd). Starts at us-south.

Mapping fields

You answer these once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
secretGroupIdSecret grouptextnoyesdefault, or a group ID from the instance's Secret groups page. We read and write arbitrary secrets in this group only, and pruning deletes every arbitrary secret in it that this environment lacks. Starts at default.

Required permissions

We probe for these when we verify the connection.

PermissionDirectionsBlockingWithout it
Readerevery directionyesPreview cannot list the secret group.
SecretsReaderevery directionyesImport cannot read a value, and export cannot tell an unchanged value from a new one.
WriterexportyesExport cannot create a secret or add a version.
ManagerexportnoPrune cannot remove a secret.