Reference
IBM Cloud Secrets Manager
Sync an environment with the arbitrary secrets in one Secrets Manager secret group.
Sync an environment with the arbitrary secrets in one Secrets Manager secret group.
Connection
| What | This provider |
|---|---|
| Vendor | IBM Cloud |
| Key | ibm-secrets-manager |
| Availability | available. You can connect it today. |
| Credential we hold | ibm-iam-key |
| Values read back | yes |
| Activation | immediate |
Directions
| Direction | What it does |
|---|---|
import | We read names and values out of the store into your environment. |
export | We write names and values from your environment into the store. |
Activation
immediate. The running app sees a new value at once.
Conflict policies
| Direction | Policies you can pick |
|---|---|
import | skip_existing, new_version, fail |
export | create_only, overwrite, overwrite_and_prune |
How syncs work says what each one does.
Connect
Paste a credential from the vendor. We seal it and never show it again.
| Field | Label | Kind | Required | What it is |
|---|---|---|---|---|
apiKey | API key | secret; we mask it here and seal it | yes | Create one under Manage, Access (IAM), then API keys, for a service ID with a role on this instance. We exchange it for a one-hour token on every run and never store the token. |
Connection fields
You set these when you connect. Every mapping on the connection shares them.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
instanceId | Instance ID | text | yes | no | In the Secrets Manager instance, open Endpoints. The ID is the first part of the public endpoint's host. |
region | Region | choice | yes | yes | The region in the instance's public endpoint. One of Dallas (us-south), Washington DC (us-east), Toronto (ca-tor), Montreal (ca-mon), Sao Paulo (br-sao), London (eu-gb), Frankfurt (eu-de), Madrid (eu-es), Tokyo (jp-tok), Osaka (jp-osa), Sydney (au-syd). Starts at us-south. |
Mapping fields
You answer these once per environment you map.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
secretGroupId | Secret group | text | no | yes | default, or a group ID from the instance's Secret groups page. We read and write arbitrary secrets in this group only, and pruning deletes every arbitrary secret in it that this environment lacks. Starts at default. |
Required permissions
We probe for these when we verify the connection.
| Permission | Directions | Blocking | Without it |
|---|---|---|---|
Reader | every direction | yes | Preview cannot list the secret group. |
SecretsReader | every direction | yes | Import cannot read a value, and export cannot tell an unchanged value from a new one. |
Writer | export | yes | Export cannot create a secret or add a version. |
Manager | export | no | Prune cannot remove a secret. |