Penv Cloud
Start free
Docs
Reference

OCI Vault

Import secrets from an OCI vault, or export to it. We never delete a secret there.

Import secrets from an OCI vault, or export to it. We never delete a secret there.

Connection

WhatThis provider
VendorOracle Cloud Infrastructure
Keyoci-vault-secrets
Availabilityavailable. You can connect it today.
Credential we holdoci-api-key
Values read backyes
Activationimmediate

Directions

DirectionWhat it does
importWe read names and values out of the store into your environment.
exportWe write names and values from your environment into the store.

Activation

immediate. The running app sees a new value at once.

Conflict policies

DirectionPolicies you can pick
importskip_existing, new_version, fail
exportcreate_only, overwrite

How syncs work says what each one does.

Connect

Paste a credential from the vendor. We seal it and never show it again.

FieldLabelKindRequiredWhat it is
tenancyIdTenancy OCIDtextyesUnder Profile, then Tenancy.
userIdUser OCIDtextyesUnder Profile, then My profile. A dedicated user in a group with the policies below is safest.
fingerprintKey fingerprinttextyesShown beside the key under My profile, then API keys.
privateKeyPrivate keysecret; we mask it here and seal ityesThe PEM file OCI generated when you added the API key. It must not have a passphrase.
regionRegiontextyesThe region identifier of the vault.

Mapping fields

You answer these once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
compartmentIdCompartment OCIDtextyesnoThe compartment the secrets live in, from Identity, then Compartments.
vaultIdVault OCIDtextyesnoFrom the vault's details page under Key Management and Secret Management, then Vault. A secret pending deletion stops any run that reads or writes it, until you cancel its deletion in OCI.
keyIdMaster encryption key OCIDtextyesnoA symmetric key in that vault. OCI encrypts every secret we create with it.

Required permissions

We probe for these when we verify the connection.

PermissionDirectionsBlockingWithout it
api-signing-keyevery directionyesWe cannot sign a request with this key, so nothing can be read or written.
read secret-familyevery directionyesPreview cannot list the vault's secrets, and import cannot read a value.
manage secret-familyexportyesExport cannot create a secret or add a version.
use vaultsexportyesExport cannot create a secret in the vault.
use keysexportyesExport cannot encrypt a new secret with the master key.