Hashicorp Vault
HashiCorp Vault is an Identity-based secrets management. This connector integrates HashiCorp Vault API version 1 with Swimlane Turbine.
Prerequisites
HashiCorp Vault asset requires URL and API Key for accessing Vault API's.
Connector Setup
Obtaining an API token and Url:
- Launch the HCP Portal and login.
- Click Vault in the left navigation pane.
- In the Vault clusters pane, click vault-cluster.
- Under Cluster URLs, click Public Cluster URL.
- Under Quick actions, click generate token to get API key.
Capabilities
The HashiCorp Vault connector provides the following capabilities:
- Read Secret
- List Secrets
- Create/Update secret
- Delete secret
Action setup
Create/Update secret action:
- Navigate to connector action interface
- Click on add property.
- Select value type i.e string or object etc.
- Give key name as per requirement and define its value. (Note: Location and path must exist in vault prior creating or updating secret.)
Notes
- For More Information on API's refer Documentation
- For More Information on Namespace refer Namespace
- For More Information on Tokens refer Token
Additional Documentation
Configurations
API Key Authentication
Authenticates using an API Key
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
X-Vault-Token | API key | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Create/Update Secret
Creates or Updates a secret at the specified location and path. If the value does not yet exist it will create a new one. The calling token must have acl policy accordingly.
Endpoint
- URL: v1/{{location}}/{{path}}
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.location | string | Required | Location of the kv secrets engine. |
path_parameters.path | string | Required | The path where the secret is stored. |
headers | object | Required | HTTP headers for the request |
headers.X-Vault-Namespace | string | Required | Namespace where the kv secrets engine is created. |
Input Example
{"json_body":{"foo1":"bar"},"path_parameters":{"location":"kv","path":"my-secret"},"headers":{"X-Vault-Namespace":"admin"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":204,"response_headers":{"Cache-Control":"no-store","Content-Type":"application/json","Date":"Thu, 18 Jan 2024 05:16:22 GMT","Ngrok-Trace-Id":"56648082a69a40dc1420807cd86e6cf7","Strict-Transport-Security":"max-age=31536000; includeSubDomains"},"reason":"No Content","response_text":""}
Delete Secret
Deletes the secret at the specified path.
Endpoint
- URL: v1/{{location}}/{{path}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.location | string | Required | Location of the kv secrets engine. |
path_parameters.path | string | Required | The path where the secret is stored. |
headers | object | Required | HTTP headers for the request |
headers.X-Vault-Namespace | string | Required | Namespace where the kv secrets engine is created. |
Input Example
{"path_parameters":{"location":"kv","path":"my-secret"},"headers":{"X-Vault-Namespace":"admin"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":204,"response_headers":{"Cache-Control":"no-store","Content-Type":"application/json","Date":"Thu, 18 Jan 2024 05:15:16 GMT","Ngrok-Trace-Id":"f892e0f7159cf129f042c158e43dcf94","Strict-Transport-Security":"max-age=31536000; includeSubDomains"},"reason":"No Content","response_text":""}
List Secrets
Lists key names at the specified path where path being the folder.
Endpoint
- URL: v1/{{location}}/{{path}}
- Method: LIST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.location | string | Required | Location of the kv secrets engine. |
path_parameters.path | string | Optional | Parent folder of the secret path. |
headers | object | Required | HTTP headers for the request |
headers.X-Vault-Namespace | string | Required | Namespace where the kv secrets engine is created. |
Input Example
{"path_parameters":{"location":"kv","path":"my-secret"},"headers":{"X-Vault-Namespace":"admin"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
request_id | string | Unique identifier |
lease_id | string | Unique identifier |
renewable | boolean | Output field: renewable |
lease_duration | number | Output field: lease_duration |
data | object | Response data |
data.keys | array | Response data |
wrap_info | object | Output field: wrap_info |
warnings | object | Output field: warnings |
auth | object | Output field: auth |
Output Example
{"status_code":200,"response_headers":{"Cache-Control":"no-store","Content-Length":"195","Content-Type":"application/json","Date":"Thu, 18 Jan 2024 05:18:10 GMT","Ngrok-Trace-Id":"4bd8b5dd4341002517d87250b6ab4274","Strict-Transport-Security":"max-age=31536000; includeSubDomains"},"reason":"OK","json_body":{"request_id":"c011d417-ce25-3cb8-b9ee-617bfc6c23f3","lease_id":"","renewable":false,"lease_duration":0,"data":{"keys":[]},"wrap_info":null,"warnings":null,"auth":null}}
Read Secret
Retrieves the secret at the specified path.
Endpoint
- URL: v1/{{location}}/{{path}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.location | string | Required | Location of the kv secrets engine. |
path_parameters.path | string | Required | The path where the secret is stored. |
headers | object | Required | HTTP headers for the request |
headers.X-Vault-Namespace | string | Required | Namespace where the kv secrets engine is created. |
Input Example
{"path_parameters":{"location":"kv","path":"my-secret"},"headers":{"X-Vault-Namespace":"admin"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
request_id | string | Unique identifier |
lease_id | string | Unique identifier |
renewable | boolean | Output field: renewable |
lease_duration | number | Output field: lease_duration |
data | object | Response data |
data.first | string | Response data |
wrap_info | object | Output field: wrap_info |
warnings | object | Output field: warnings |
auth | object | Output field: auth |
Output Example
{"status_code":200,"response_headers":{"Cache-Control":"no-store","Content-Length":"179","Content-Type":"application/json","Date":"Thu, 18 Jan 2024 05:12:46 GMT","Ngrok-Trace-Id":"e4e63fad77aa76afa1e3d879b3a442a9","Strict-Transport-Security":"max-age=31536000; includeSubDomains"},"reason":"OK","json_body":{"request_id":"cb9bd138-14ab-1606-d683-d27d64210966","lease_id":"","renewable":false,"lease_duration":2764800,"data":{"first":"one"},"wrap_info":null,"warnings":null,"auth":null}}
Response Headers
Header | Description | Example |
|---|---|---|
Cache-Control | Directives for caching mechanisms | no-store |
Content-Length | The length of the response body in bytes | 179 |
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 18 Jan 2024 05:16:22 GMT |
Ngrok-Trace-Id | HTTP response header: Ngrok-Trace-Id | 4bd8b5dd4341002517d87250b6ab4274 |
Strict-Transport-Security | HTTP response header: Strict-Transport-Security | max-age=31536000; includeSubDomains |