Reference
Tencent Cloud Secrets Manager
Move secrets to and from Tencent Cloud Secrets Manager in one region.
Move secrets to and from Tencent Cloud Secrets Manager in one region.
Connection
| What | This provider |
|---|---|
| Vendor | Tencent Cloud |
| Key | tencent-ssm-secrets |
| Availability | available. You can connect it today. |
| Credential we hold | tencent-api-key |
| Values read back | yes |
| Activation | immediate |
Directions
| Direction | What it does |
|---|---|
import | We read names and values out of the store into your environment. |
export | We write names and values from your environment into the store. |
Activation
immediate. The running app sees a new value at once.
Conflict policies
| Direction | Policies you can pick |
|---|---|
import | skip_existing, new_version, fail |
export | create_only, overwrite, overwrite_and_prune |
How syncs work says what each one does.
Connect
Paste a credential from the vendor. We seal it and never show it again.
| Field | Label | Kind | Required | What it is |
|---|---|---|---|---|
secretId | SecretId | text | yes | In the Tencent Cloud console, open Cloud Access Management, then API Keys. |
secretKey | SecretKey | secret; we mask it here and seal it | yes | Shown beside the SecretId. Use a sub-user key with the ssm actions listed below. |
Connection fields
You set these when you connect. Every mapping on the connection shares them.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
region | Region | text | yes | no | The region that holds the secrets. One connection covers one region. |
Mapping fields
You answer these once per environment you map.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
namePrefix | Secret name prefix | text | yes | no | We name each secret prefix-KEY and only touch secrets under this prefix. We never re-enable or restore a secret: an export to a disabled or pending-delete one fails until you re-enable or restore it in the console. |
Required permissions
We probe for these when we verify the connection.
| Permission | Directions | Blocking | Without it |
|---|---|---|---|
ssm:ListSecrets | every direction | yes | Preview cannot list the secrets under this prefix. |
ssm:GetSecretValue | import | yes | Import cannot read any value. |
ssm:CreateSecret | export | yes | Export cannot create a new secret. |
ssm:UpdateSecret | export | yes | Export cannot change a value that is already there. |
ssm:PutSecretValue | export | no | Export cannot write to a secret created outside penv without an SSM_Current version. |
ssm:DisableSecret | export | no | The overwrite_and_prune policy cannot remove secrets. |
ssm:DeleteSecret | export | no | The overwrite_and_prune policy cannot remove secrets. |