Reference
OCI Vault
Import secrets from an OCI vault, or export to it. We never delete a secret there.
Import secrets from an OCI vault, or export to it. We never delete a secret there.
Connection
| What | This provider |
|---|---|
| Vendor | Oracle Cloud Infrastructure |
| Key | oci-vault-secrets |
| Availability | available. You can connect it today. |
| Credential we hold | oci-api-key |
| Values read back | yes |
| Activation | immediate |
Directions
| Direction | What it does |
|---|---|
import | We read names and values out of the store into your environment. |
export | We write names and values from your environment into the store. |
Activation
immediate. The running app sees a new value at once.
Conflict policies
| Direction | Policies you can pick |
|---|---|
import | skip_existing, new_version, fail |
export | create_only, overwrite |
How syncs work says what each one does.
Connect
Paste a credential from the vendor. We seal it and never show it again.
| Field | Label | Kind | Required | What it is |
|---|---|---|---|---|
tenancyId | Tenancy OCID | text | yes | Under Profile, then Tenancy. |
userId | User OCID | text | yes | Under Profile, then My profile. A dedicated user in a group with the policies below is safest. |
fingerprint | Key fingerprint | text | yes | Shown beside the key under My profile, then API keys. |
privateKey | Private key | secret; we mask it here and seal it | yes | The PEM file OCI generated when you added the API key. It must not have a passphrase. |
region | Region | text | yes | The region identifier of the vault. |
Mapping fields
You answer these once per environment you map.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
compartmentId | Compartment OCID | text | yes | no | The compartment the secrets live in, from Identity, then Compartments. |
vaultId | Vault OCID | text | yes | no | From the vault's details page under Key Management and Secret Management, then Vault. A secret pending deletion stops any run that reads or writes it, until you cancel its deletion in OCI. |
keyId | Master encryption key OCID | text | yes | no | A symmetric key in that vault. OCI encrypts every secret we create with it. |
Required permissions
We probe for these when we verify the connection.
| Permission | Directions | Blocking | Without it |
|---|---|---|---|
api-signing-key | every direction | yes | We cannot sign a request with this key, so nothing can be read or written. |
read secret-family | every direction | yes | Preview cannot list the vault's secrets, and import cannot read a value. |
manage secret-family | export | yes | Export cannot create a secret or add a version. |
use vaults | export | yes | Export cannot create a secret in the vault. |
use keys | export | yes | Export cannot encrypt a new secret with the master key. |