Skip to main content

secrets

Creates, updates, deletes, gets or lists a secrets resource.

Overview​

Namesecrets
TypeResource
Idoci.vault.secrets

Fields​

The following fields are returned by SELECT queries:

The specified secret object.

NameDatatypeDescription
idstringThe OCID of the secret.
compartmentIdstringThe OCID of the compartment where you want to create the secret.
currentVersionNumberinteger (int64)The version number of the secret version that's currently in use.
definedTagsobjectDefined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}}
descriptionstringA brief description of the secret. Avoid entering confidential information.
freeformTagsobjectFree-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"}
isAutoGenerationEnabledbooleanThe value of this flag determines whether or not secret content will be generated automatically.
keyIdstringThe OCID of the master encryption key that is used to encrypt the secret. You must specify a symmetric key to encrypt the secret during import to the vault. You cannot encrypt secrets with asymmetric keys. Furthermore, the key must exist in the vault that you specify.
lastRotationTimestring (date-time)A property indicating when the secret was last rotated successfully, expressed in [RFC 3339](https:​//tools.ietf.org/html/rfc3339) timestamp format. Example: 2019-04-03T21:10:29.600Z
lifecycleDetailsstringAdditional information about the current lifecycle state of the secret.
lifecycleStatestringThe current lifecycle state of the secret. (CREATING, ACTIVE, UPDATING, DELETING, DELETED, SCHEDULING_DELETION, PENDING_DELETION, CANCELLING_DELETION, FAILED)
metadataobjectAdditional metadata that you can use to provide context about how to use the secret or during rotation or other administrative tasks. For example, for a secret that you use to connect to a database, the additional metadata might specify the connection endpoint and the connection string. Provide additional metadata as key-value pairs.
nextRotationTimestring (date-time)A property indicating when the secret is scheduled to be rotated, expressed in [RFC 3339](https:​//tools.ietf.org/html/rfc3339) timestamp format. Example: 2019-04-03T21:10:29.600Z
rotationConfigobjectDefines the frequency of the rotation and the information about the target system
rotationStatusstringAdditional information about the status of the secret rotation (IN_PROGRESS, SCHEDULED, NOT_ENABLED, CANCELLING)
secretGenerationContextobjectCaptures a configurable set of secret generation rules such as length, base characters, additional characters, and so on. (x-example: {<br /> "generationType": "SSH_KEY",<br /> "generationTemplate": "RSA_3072"<br />}<br />)
secretNamestringThe user-friendly name of the secret. Avoid entering confidential information.
secretRulesarrayA list of rules that control how the secret is used and managed.
timeCreatedstring (date-time)A property indicating when the secret was created, expressed in [RFC 3339](https:​//tools.ietf.org/html/rfc3339) timestamp format. Example: 2019-04-03T21:10:29.600Z
timeOfCurrentVersionExpirystring (date-time)An optional property indicating when the current secret version will expire, expressed in [RFC 3339](https:​//tools.ietf.org/html/rfc3339) timestamp format. Example: 2019-04-03T21:10:29.600Z
timeOfDeletionstring (date-time)An optional property indicating when to delete the secret, expressed in [RFC 3339](https:​//tools.ietf.org/html/rfc3339) timestamp format. Example: 2019-04-03T21:10:29.600Z
vaultIdstringThe OCID of the vault where the secret exists.

Methods​

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
getselectsecretId, regionopc-request-idGets information about the specified secret.
listselectcompartmentId, regionname, limit, page, opc-request-id, sortBy, sortOrder, vaultId, lifecycleStateLists all secrets in the specified vault and compartment.
createinsertregion, vaultId, secretName, compartmentId, keyIdopc-request-id, opc-retry-tokenCreates a new secret according to the details of the request.<br /><br />This operation is not supported by the Oracle Cloud Infrastructure Terraform Provider.<br />
updateupdatesecretId, regionif-match, opc-request-idUpdates the properties of a secret. Specifically, you can update the version number of the secret to make<br />that version number the current version. You can also update a secret's description, its free-form or defined tags, rules<br />and the secret contents. Updating the secret content automatically creates a new secret version. You cannot, however, update the current secret version number, secret contents, and secret rules at the<br />same time. Furthermore, the secret must in an ACTIVE lifecycle state to be updated.<br /><br />This operation is not supported by the Oracle Cloud Infrastructure Terraform Provider.<br />
cancel_secret_deletionexecsecretId, regionif-match, opc-request-idCancels the pending deletion of the specified secret. Canceling<br />a scheduled deletion restores the secret's lifecycle state to what<br />it was before you scheduled the secret for deletion.<br />
cancel_secret_rotationexecsecretId, regionif-match, opc-request-idCancels the ongoing secret rotation. The cancellation is contingent on how<br />far the rotation process has progressed. Upon cancelling a rotation, all <br />future rotations are also disabled.<br />
change_compartmentexecsecretId, region, compartmentIdif-match, opc-request-id, opc-retry-tokenMoves a secret into a different compartment within the same tenancy. For information about<br />moving resources between compartments, see [Moving Resources to a Different Compartment](/iaas/Content/Identity/Tasks/managingcompartments.htm#moveRes).<br /><br />When provided, if-match is checked against the ETag values of the secret.<br />
rotate_secretexecsecretId, regionif-match, opc-request-id, opc-retry-tokenAPI to force rotation of an existing secret in Vault and the specified target system; expects secret to have a valid Target System Details object<br />
schedule_secret_deletionexecsecretId, regionif-match, opc-request-idSchedules the deletion of the specified secret. This sets the lifecycle state of the secret<br />to PENDING_DELETION and then deletes it after the specified retention period ends.<br />

Parameters​

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
compartmentIdstringThe OCID of the compartment.
regionstringOCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION)
secretIdstringThe OCID of the secret.
if-matchstringFor optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value.
lifecycleStatestringA filter that returns only resources that match the specified lifecycle state. The state value is case-insensitive.
limitintegerThe maximum number of items to return in a paginated "List" call.
namestringThe secret name.
opc-request-idstringUnique identifier for the request. If provided, the returned request ID will include this value. Otherwise, a random request ID will be generated by the service.
opc-retry-tokenstringA token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
pagestringThe value of the opc-next-page response header from the previous "List" call.
sortBystringThe field to sort by. You can specify only one sort order. The default order for TIMECREATED is descending. The default order for NAME is ascending.
sortOrderstringThe sort order to use, either ascending (ASC) or descending (DESC).
vaultIdstringThe OCID of the vault.

SELECT examples​

Gets information about the specified secret.

SELECT
id,
compartmentId,
currentVersionNumber,
definedTags,
description,
freeformTags,
isAutoGenerationEnabled,
keyId,
lastRotationTime,
lifecycleDetails,
lifecycleState,
metadata,
nextRotationTime,
rotationConfig,
rotationStatus,
secretGenerationContext,
secretName,
secretRules,
timeCreated,
timeOfCurrentVersionExpiry,
timeOfDeletion,
vaultId
FROM oci.vault.secrets
WHERE secretId = '{{ secretId }}' -- required
AND region = '{{ region }}' -- required
AND opc-request-id = '{{ opc-request-id }}'
;

INSERT examples​

Creates a new secret according to the details of the request.<br /><br />This operation is not supported by the Oracle Cloud Infrastructure Terraform Provider.<br />

INSERT INTO oci.vault.secrets (
compartmentId,
definedTags,
description,
enableAutoGeneration,
freeformTags,
keyId,
metadata,
rotationConfig,
secretContent,
secretGenerationContext,
secretName,
secretRules,
vaultId,
region,
opc-request-id,
opc-retry-token
)
SELECT
'{{ compartmentId }}' /* required */,
'{{ definedTags }}',
'{{ description }}',
{{ enableAutoGeneration }},
'{{ freeformTags }}',
'{{ keyId }}' /* required */,
'{{ metadata }}',
'{{ rotationConfig }}',
'{{ secretContent }}',
'{{ secretGenerationContext }}',
'{{ secretName }}' /* required */,
'{{ secretRules }}',
'{{ vaultId }}' /* required */,
'{{ region }}',
'{{ opc-request-id }}',
'{{ opc-retry-token }}'
RETURNING
id,
compartmentId,
currentVersionNumber,
definedTags,
description,
freeformTags,
isAutoGenerationEnabled,
keyId,
lastRotationTime,
lifecycleDetails,
lifecycleState,
metadata,
nextRotationTime,
rotationConfig,
rotationStatus,
secretGenerationContext,
secretName,
secretRules,
timeCreated,
timeOfCurrentVersionExpiry,
timeOfDeletion,
vaultId
;

UPDATE examples​

Updates the properties of a secret. Specifically, you can update the version number of the secret to make<br />that version number the current version. You can also update a secret's description, its free-form or defined tags, rules<br />and the secret contents. Updating the secret content automatically creates a new secret version. You cannot, however, update the current secret version number, secret contents, and secret rules at the<br />same time. Furthermore, the secret must in an ACTIVE lifecycle state to be updated.<br /><br />This operation is not supported by the Oracle Cloud Infrastructure Terraform Provider.<br />

UPDATE oci.vault.secrets
SET
currentVersionNumber = {{ currentVersionNumber }},
definedTags = '{{ definedTags }}',
description = '{{ description }}',
enableAutoGeneration = {{ enableAutoGeneration }},
freeformTags = '{{ freeformTags }}',
metadata = '{{ metadata }}',
rotationConfig = '{{ rotationConfig }}',
secretContent = '{{ secretContent }}',
secretGenerationContext = '{{ secretGenerationContext }}',
secretRules = '{{ secretRules }}'
WHERE
secretId = '{{ secretId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match}}'
AND opc-request-id = '{{ opc-request-id}}'
RETURNING
id,
compartmentId,
currentVersionNumber,
definedTags,
description,
freeformTags,
isAutoGenerationEnabled,
keyId,
lastRotationTime,
lifecycleDetails,
lifecycleState,
metadata,
nextRotationTime,
rotationConfig,
rotationStatus,
secretGenerationContext,
secretName,
secretRules,
timeCreated,
timeOfCurrentVersionExpiry,
timeOfDeletion,
vaultId;

Lifecycle Methods​

Cancels the pending deletion of the specified secret. Canceling<br />a scheduled deletion restores the secret's lifecycle state to what<br />it was before you scheduled the secret for deletion.<br />

EXEC oci.vault.secrets.cancel_secret_deletion
@secretId='{{ secretId }}' --required,
@region='{{ region }}' --required,
@if-match='{{ if-match }}',
@opc-request-id='{{ opc-request-id }}'
;