secrets
Creates, updates, deletes, gets or lists a secrets resource.
Overview​
| Name | secrets |
| Type | Resource |
| Id | oci.vault.secrets |
Fields​
The following fields are returned by SELECT queries:
- get
- list
The specified secret object.
| Name | Datatype | Description |
|---|---|---|
id | string | The OCID of the secret. |
compartmentId | string | The OCID of the compartment where you want to create the secret. |
currentVersionNumber | integer (int64) | The version number of the secret version that's currently in use. |
definedTags | object | Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}} |
description | string | A brief description of the secret. Avoid entering confidential information. |
freeformTags | object | Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"} |
isAutoGenerationEnabled | boolean | The value of this flag determines whether or not secret content will be generated automatically. |
keyId | string | The OCID of the master encryption key that is used to encrypt the secret. You must specify a symmetric key to encrypt the secret during import to the vault. You cannot encrypt secrets with asymmetric keys. Furthermore, the key must exist in the vault that you specify. |
lastRotationTime | string (date-time) | A property indicating when the secret was last rotated successfully, expressed in [RFC 3339](https:​//tools.ietf.org/html/rfc3339) timestamp format. Example: 2019-04-03T21:10:29.600Z |
lifecycleDetails | string | Additional information about the current lifecycle state of the secret. |
lifecycleState | string | The current lifecycle state of the secret. (CREATING, ACTIVE, UPDATING, DELETING, DELETED, SCHEDULING_DELETION, PENDING_DELETION, CANCELLING_DELETION, FAILED) |
metadata | object | Additional metadata that you can use to provide context about how to use the secret or during rotation or other administrative tasks. For example, for a secret that you use to connect to a database, the additional metadata might specify the connection endpoint and the connection string. Provide additional metadata as key-value pairs. |
nextRotationTime | string (date-time) | A property indicating when the secret is scheduled to be rotated, expressed in [RFC 3339](https:​//tools.ietf.org/html/rfc3339) timestamp format. Example: 2019-04-03T21:10:29.600Z |
rotationConfig | object | Defines the frequency of the rotation and the information about the target system |
rotationStatus | string | Additional information about the status of the secret rotation (IN_PROGRESS, SCHEDULED, NOT_ENABLED, CANCELLING) |
secretGenerationContext | object | Captures a configurable set of secret generation rules such as length, base characters, additional characters, and so on. (x-example: {<br /> "generationType": "SSH_KEY",<br /> "generationTemplate": "RSA_3072"<br />}<br />) |
secretName | string | The user-friendly name of the secret. Avoid entering confidential information. |
secretRules | array | A list of rules that control how the secret is used and managed. |
timeCreated | string (date-time) | A property indicating when the secret was created, expressed in [RFC 3339](https:​//tools.ietf.org/html/rfc3339) timestamp format. Example: 2019-04-03T21:10:29.600Z |
timeOfCurrentVersionExpiry | string (date-time) | An optional property indicating when the current secret version will expire, expressed in [RFC 3339](https:​//tools.ietf.org/html/rfc3339) timestamp format. Example: 2019-04-03T21:10:29.600Z |
timeOfDeletion | string (date-time) | An optional property indicating when to delete the secret, expressed in [RFC 3339](https:​//tools.ietf.org/html/rfc3339) timestamp format. Example: 2019-04-03T21:10:29.600Z |
vaultId | string | The OCID of the vault where the secret exists. |
The details of the secret, excluding the contents of the secret.
| Name | Datatype | Description |
|---|---|---|
id | string | The OCID of the secret. |
compartmentId | string | The OCID of the compartment that contains the secret. |
definedTags | object | Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}} |
description | string | A brief description of the secret. |
freeformTags | object | Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"} |
isAutoGenerationEnabled | boolean | The value of this flag determines whether or not secret content will be generated automatically. |
keyId | string | The OCID of the master encryption key that is used to encrypt the secret. You must specify a symmetric key to encrypt the secret during import to the vault. You cannot encrypt secrets with asymmetric keys. Furthermore, the key must exist in the vault that you specify. |
lastRotationTime | string (date-time) | A property indicating when the secret was last rotated successfully, expressed in [RFC 3339](https:​//tools.ietf.org/html/rfc3339) timestamp format. Example: 2019-04-03T21:10:29.600Z |
lifecycleDetails | string | Additional information about the secret's current lifecycle state. |
lifecycleState | string | The current lifecycle state of the secret. (CREATING, ACTIVE, UPDATING, DELETING, DELETED, SCHEDULING_DELETION, PENDING_DELETION, CANCELLING_DELETION, FAILED) |
nextRotationTime | string (date-time) | A property indicating when the secret is scheduled to be rotated, expressed in [RFC 3339](https:​//tools.ietf.org/html/rfc3339) timestamp format. Example: 2019-04-03T21:10:29.600Z |
rotationConfig | object | Defines the frequency of the rotation and the information about the target system |
rotationStatus | string | Additional information about the status of the secret rotation (x-obmcs-enumref: #/definitions/Secret/rotationStatus) |
secretGenerationContext | object | Captures a configurable set of secret generation rules such as length, base characters, additional characters, and so on. (x-example: {<br /> "generationType": "SSH_KEY",<br /> "generationTemplate": "RSA_3072"<br />}<br />) |
secretName | string | The name of the secret. |
systemTags | object | System tags for this resource. Each key is predefined and scoped to a namespace. Example: {"orcl-cloud": {"free-tier-retained": "true"}} |
timeCreated | string (date-time) | A property indicating when the secret was created, expressed in [RFC 3339](https:​//tools.ietf.org/html/rfc3339) timestamp format. Example: 2019-04-03T21:10:29.600Z |
timeOfCurrentVersionExpiry | string (date-time) | An optional property indicating when the current secret version will expire, expressed in [RFC 3339](https:​//tools.ietf.org/html/rfc3339) timestamp format. Example: 2019-04-03T21:10:29.600Z |
timeOfDeletion | string (date-time) | An optional property indicating when to delete the secret, expressed in [RFC 3339](https:​//tools.ietf.org/html/rfc3339) timestamp format. Example: 2019-04-03T21:10:29.600Z |
vaultId | string | The OCID of the Vault in which the secret exists |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | secretId, region | opc-request-id | Gets information about the specified secret. |
list | select | compartmentId, region | name, limit, page, opc-request-id, sortBy, sortOrder, vaultId, lifecycleState | Lists all secrets in the specified vault and compartment. |
create | insert | region, vaultId, secretName, compartmentId, keyId | opc-request-id, opc-retry-token | Creates a new secret according to the details of the request.<br /><br />This operation is not supported by the Oracle Cloud Infrastructure Terraform Provider.<br /> |
update | update | secretId, region | if-match, opc-request-id | Updates the properties of a secret. Specifically, you can update the version number of the secret to make<br />that version number the current version. You can also update a secret's description, its free-form or defined tags, rules<br />and the secret contents. Updating the secret content automatically creates a new secret version. You cannot, however, update the current secret version number, secret contents, and secret rules at the<br />same time. Furthermore, the secret must in an ACTIVE lifecycle state to be updated.<br /><br />This operation is not supported by the Oracle Cloud Infrastructure Terraform Provider.<br /> |
cancel_secret_deletion | exec | secretId, region | if-match, opc-request-id | Cancels the pending deletion of the specified secret. Canceling<br />a scheduled deletion restores the secret's lifecycle state to what<br />it was before you scheduled the secret for deletion.<br /> |
cancel_secret_rotation | exec | secretId, region | if-match, opc-request-id | Cancels the ongoing secret rotation. The cancellation is contingent on how<br />far the rotation process has progressed. Upon cancelling a rotation, all <br />future rotations are also disabled.<br /> |
change_compartment | exec | secretId, region, compartmentId | if-match, opc-request-id, opc-retry-token | Moves a secret into a different compartment within the same tenancy. For information about<br />moving resources between compartments, see [Moving Resources to a Different Compartment](/iaas/Content/Identity/Tasks/managingcompartments.htm#moveRes).<br /><br />When provided, if-match is checked against the ETag values of the secret.<br /> |
rotate_secret | exec | secretId, region | if-match, opc-request-id, opc-retry-token | API to force rotation of an existing secret in Vault and the specified target system; expects secret to have a valid Target System Details object<br /> |
schedule_secret_deletion | exec | secretId, region | if-match, opc-request-id | Schedules the deletion of the specified secret. This sets the lifecycle state of the secret<br />to PENDING_DELETION and then deletes it after the specified retention period ends.<br /> |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
compartmentId | string | The OCID of the compartment. |
region | string | OCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION) |
secretId | string | The OCID of the secret. |
if-match | string | For optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value. |
lifecycleState | string | A filter that returns only resources that match the specified lifecycle state. The state value is case-insensitive. |
limit | integer | The maximum number of items to return in a paginated "List" call. |
name | string | The secret name. |
opc-request-id | string | Unique identifier for the request. If provided, the returned request ID will include this value. Otherwise, a random request ID will be generated by the service. |
opc-retry-token | string | A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected). |
page | string | The value of the opc-next-page response header from the previous "List" call. |
sortBy | string | The field to sort by. You can specify only one sort order. The default order for TIMECREATED is descending. The default order for NAME is ascending. |
sortOrder | string | The sort order to use, either ascending (ASC) or descending (DESC). |
vaultId | string | The OCID of the vault. |
SELECT examples​
- get
- list
Gets information about the specified secret.
SELECT
id,
compartmentId,
currentVersionNumber,
definedTags,
description,
freeformTags,
isAutoGenerationEnabled,
keyId,
lastRotationTime,
lifecycleDetails,
lifecycleState,
metadata,
nextRotationTime,
rotationConfig,
rotationStatus,
secretGenerationContext,
secretName,
secretRules,
timeCreated,
timeOfCurrentVersionExpiry,
timeOfDeletion,
vaultId
FROM oci.vault.secrets
WHERE secretId = '{{ secretId }}' -- required
AND region = '{{ region }}' -- required
AND opc-request-id = '{{ opc-request-id }}'
;
Lists all secrets in the specified vault and compartment.
SELECT
id,
compartmentId,
definedTags,
description,
freeformTags,
isAutoGenerationEnabled,
keyId,
lastRotationTime,
lifecycleDetails,
lifecycleState,
nextRotationTime,
rotationConfig,
rotationStatus,
secretGenerationContext,
secretName,
systemTags,
timeCreated,
timeOfCurrentVersionExpiry,
timeOfDeletion,
vaultId
FROM oci.vault.secrets
WHERE compartmentId = '{{ compartmentId }}' -- required
AND region = '{{ region }}' -- required
AND name = '{{ name }}'
AND limit = '{{ limit }}'
AND page = '{{ page }}'
AND opc-request-id = '{{ opc-request-id }}'
AND sortBy = '{{ sortBy }}'
AND sortOrder = '{{ sortOrder }}'
AND vaultId = '{{ vaultId }}'
AND lifecycleState = '{{ lifecycleState }}'
;
INSERT examples​
- create
- Manifest
Creates a new secret according to the details of the request.<br /><br />This operation is not supported by the Oracle Cloud Infrastructure Terraform Provider.<br />
INSERT INTO oci.vault.secrets (
compartmentId,
definedTags,
description,
enableAutoGeneration,
freeformTags,
keyId,
metadata,
rotationConfig,
secretContent,
secretGenerationContext,
secretName,
secretRules,
vaultId,
region,
opc-request-id,
opc-retry-token
)
SELECT
'{{ compartmentId }}' /* required */,
'{{ definedTags }}',
'{{ description }}',
{{ enableAutoGeneration }},
'{{ freeformTags }}',
'{{ keyId }}' /* required */,
'{{ metadata }}',
'{{ rotationConfig }}',
'{{ secretContent }}',
'{{ secretGenerationContext }}',
'{{ secretName }}' /* required */,
'{{ secretRules }}',
'{{ vaultId }}' /* required */,
'{{ region }}',
'{{ opc-request-id }}',
'{{ opc-retry-token }}'
RETURNING
id,
compartmentId,
currentVersionNumber,
definedTags,
description,
freeformTags,
isAutoGenerationEnabled,
keyId,
lastRotationTime,
lifecycleDetails,
lifecycleState,
metadata,
nextRotationTime,
rotationConfig,
rotationStatus,
secretGenerationContext,
secretName,
secretRules,
timeCreated,
timeOfCurrentVersionExpiry,
timeOfDeletion,
vaultId
;
# Description fields are for documentation purposes
- name: secrets
props:
- name: region
value: "{{ region }}"
description: Required parameter for the secrets resource.
- name: compartmentId
value: "{{ compartmentId }}"
description: |
The OCID of the compartment where you want to create the secret.
- name: definedTags
value: "{{ definedTags }}"
description: |
Defined tags for this resource. Each key is predefined and scoped to a namespace.
For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm).
Example: `{"Operations": {"CostCenter": "42"}}`
- name: description
value: "{{ description }}"
description: |
A brief description of the secret. Avoid entering confidential information.
- name: enableAutoGeneration
value: {{ enableAutoGeneration }}
description: |
The value of this flag determines whether or not secret content will be generated automatically. If not set, it defaults to false.
- name: freeformTags
value: "{{ freeformTags }}"
description: |
Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace.
For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm).
Example: `{"Department": "Finance"}`
- name: keyId
value: "{{ keyId }}"
description: |
The OCID of the master encryption key that is used to encrypt the secret. You must specify a symmetric key to encrypt the secret during import to the vault. You cannot encrypt secrets with asymmetric keys. Furthermore, the key must exist in the vault that you specify.
- name: metadata
value: "{{ metadata }}"
description: |
Additional metadata that you can use to provide context about how to use the secret during rotation or
other administrative tasks. For example, for a secret that you use to connect to a database, the additional
metadata might specify the connection endpoint and the connection string. Provide additional metadata as key-value pairs.
- name: rotationConfig
description: |
Defines the frequency of the rotation and the information about the target system
value:
isScheduledRotationEnabled: {{ isScheduledRotationEnabled }}
rotationInterval: "{{ rotationInterval }}"
targetSystemDetails:
targetSystemType: "{{ targetSystemType }}"
- name: secretContent
description: |
The content of the secret and metadata to help identify it.
value:
contentType: "{{ contentType }}"
name: "{{ name }}"
stage: "{{ stage }}"
- name: secretGenerationContext
description: |
Captures a configurable set of secret generation rules such as length, base characters, additional characters, and so on.
value:
generationType: "{{ generationType }}"
secretTemplate: "{{ secretTemplate }}"
- name: secretName
value: "{{ secretName }}"
description: |
A user-friendly name for the secret. Secret names should be unique within a vault. Avoid entering confidential information. Valid characters are uppercase or lowercase letters, numbers, hyphens, underscores, and periods.
- name: secretRules
description: |
A list of rules to control how the secret is used and managed.
value:
- ruleType: "{{ ruleType }}"
- name: vaultId
value: "{{ vaultId }}"
description: |
The OCID of the vault where you want to create the secret.
- name: opc-request-id
value: "{{ opc-request-id }}"
description: Unique identifier for the request. If provided, the returned request ID will include this value. Otherwise, a random request ID will be generated by the service.
description: Unique identifier for the request. If provided, the returned request ID will include this value. Otherwise, a random request ID will be generated by the service.
- name: opc-retry-token
value: "{{ opc-retry-token }}"
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
UPDATE examples​
- update
Updates the properties of a secret. Specifically, you can update the version number of the secret to make<br />that version number the current version. You can also update a secret's description, its free-form or defined tags, rules<br />and the secret contents. Updating the secret content automatically creates a new secret version. You cannot, however, update the current secret version number, secret contents, and secret rules at the<br />same time. Furthermore, the secret must in an ACTIVE lifecycle state to be updated.<br /><br />This operation is not supported by the Oracle Cloud Infrastructure Terraform Provider.<br />
UPDATE oci.vault.secrets
SET
currentVersionNumber = {{ currentVersionNumber }},
definedTags = '{{ definedTags }}',
description = '{{ description }}',
enableAutoGeneration = {{ enableAutoGeneration }},
freeformTags = '{{ freeformTags }}',
metadata = '{{ metadata }}',
rotationConfig = '{{ rotationConfig }}',
secretContent = '{{ secretContent }}',
secretGenerationContext = '{{ secretGenerationContext }}',
secretRules = '{{ secretRules }}'
WHERE
secretId = '{{ secretId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match}}'
AND opc-request-id = '{{ opc-request-id}}'
RETURNING
id,
compartmentId,
currentVersionNumber,
definedTags,
description,
freeformTags,
isAutoGenerationEnabled,
keyId,
lastRotationTime,
lifecycleDetails,
lifecycleState,
metadata,
nextRotationTime,
rotationConfig,
rotationStatus,
secretGenerationContext,
secretName,
secretRules,
timeCreated,
timeOfCurrentVersionExpiry,
timeOfDeletion,
vaultId;
Lifecycle Methods​
- cancel_secret_deletion
- cancel_secret_rotation
- change_compartment
- rotate_secret
- schedule_secret_deletion
Cancels the pending deletion of the specified secret. Canceling<br />a scheduled deletion restores the secret's lifecycle state to what<br />it was before you scheduled the secret for deletion.<br />
EXEC oci.vault.secrets.cancel_secret_deletion
@secretId='{{ secretId }}' --required,
@region='{{ region }}' --required,
@if-match='{{ if-match }}',
@opc-request-id='{{ opc-request-id }}'
;
Cancels the ongoing secret rotation. The cancellation is contingent on how<br />far the rotation process has progressed. Upon cancelling a rotation, all <br />future rotations are also disabled.<br />
EXEC oci.vault.secrets.cancel_secret_rotation
@secretId='{{ secretId }}' --required,
@region='{{ region }}' --required,
@if-match='{{ if-match }}',
@opc-request-id='{{ opc-request-id }}'
;
Moves a secret into a different compartment within the same tenancy. For information about<br />moving resources between compartments, see [Moving Resources to a Different Compartment](/iaas/Content/Identity/Tasks/managingcompartments.htm#moveRes).<br /><br />When provided, if-match is checked against the ETag values of the secret.<br />
EXEC oci.vault.secrets.change_compartment
@secretId='{{ secretId }}' --required,
@region='{{ region }}' --required,
@if-match='{{ if-match }}',
@opc-request-id='{{ opc-request-id }}',
@opc-retry-token='{{ opc-retry-token }}'
@@json=
'{
"compartmentId": "{{ compartmentId }}"
}'
;
API to force rotation of an existing secret in Vault and the specified target system; expects secret to have a valid Target System Details object<br />
EXEC oci.vault.secrets.rotate_secret
@secretId='{{ secretId }}' --required,
@region='{{ region }}' --required,
@if-match='{{ if-match }}',
@opc-request-id='{{ opc-request-id }}',
@opc-retry-token='{{ opc-retry-token }}'
;
Schedules the deletion of the specified secret. This sets the lifecycle state of the secret<br />to PENDING_DELETION and then deletes it after the specified retention period ends.<br />
EXEC oci.vault.secrets.schedule_secret_deletion
@secretId='{{ secretId }}' --required,
@region='{{ region }}' --required,
@if-match='{{ if-match }}',
@opc-request-id='{{ opc-request-id }}'
@@json=
'{
"timeOfDeletion": "{{ timeOfDeletion }}"
}'
;