Penv Cloud
Start free
Docs
Reference

Tencent Cloud Secrets Manager

Move secrets to and from Tencent Cloud Secrets Manager in one region.

Move secrets to and from Tencent Cloud Secrets Manager in one region.

Connection

WhatThis provider
VendorTencent Cloud
Keytencent-ssm-secrets
Availabilityavailable. You can connect it today.
Credential we holdtencent-api-key
Values read backyes
Activationimmediate

Directions

DirectionWhat it does
importWe read names and values out of the store into your environment.
exportWe write names and values from your environment into the store.

Activation

immediate. The running app sees a new value at once.

Conflict policies

DirectionPolicies you can pick
importskip_existing, new_version, fail
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

Connect

Paste a credential from the vendor. We seal it and never show it again.

FieldLabelKindRequiredWhat it is
secretIdSecretIdtextyesIn the Tencent Cloud console, open Cloud Access Management, then API Keys.
secretKeySecretKeysecret; we mask it here and seal ityesShown beside the SecretId. Use a sub-user key with the ssm actions listed below.

Connection fields

You set these when you connect. Every mapping on the connection shares them.

FieldLabelKindRequiredAdvancedWhat it is
regionRegiontextyesnoThe region that holds the secrets. One connection covers one region.

Mapping fields

You answer these once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
namePrefixSecret name prefixtextyesnoWe name each secret prefix-KEY and only touch secrets under this prefix. We never re-enable or restore a secret: an export to a disabled or pending-delete one fails until you re-enable or restore it in the console.

Required permissions

We probe for these when we verify the connection.

PermissionDirectionsBlockingWithout it
ssm:ListSecretsevery directionyesPreview cannot list the secrets under this prefix.
ssm:GetSecretValueimportyesImport cannot read any value.
ssm:CreateSecretexportyesExport cannot create a new secret.
ssm:UpdateSecretexportyesExport cannot change a value that is already there.
ssm:PutSecretValueexportnoExport cannot write to a secret created outside penv without an SSM_Current version.
ssm:DisableSecretexportnoThe overwrite_and_prune policy cannot remove secrets.
ssm:DeleteSecretexportnoThe overwrite_and_prune policy cannot remove secrets.