Secrets
Keep credentials in vaults and hand them to workloads without putting them in configuration.
- API reference — Every HTTP endpoint of the secrets module: authentication, IAM action, parameters, bodies and status codes.
- Configuration reference — Configuration keys of the secrets module: sections, environment variables, types and defaults.
- Secrets — Keep credentials in vaults and hand them to workloads without putting them in configuration.
- Key hierarchy — How secret values are encrypted, where the master key is kept, and what losing it means.
- Names and limits — Naming rules for vaults and secrets, and the limits that apply to them.
- Permissions — The actions that govern vaults and secrets, and the roles that hold them.
- Create a vault — Create a vault in a resource group, choose its protection settings, and decide who can read it.
- Vaults — What a vault page shows, what its activity log records, and what deleting a vault does.
- Manage secrets — Add secrets to a vault, read and change their values, and delete, recover or purge them.
- Secrets in apps and functions — Reference vault secrets from an app or a function and read the values in your code.
- The .NET client — Read secrets from a vault in .NET code with the Stackship Secrets client.
- Secrets in container instances — Pass vault secrets to a container instance as environment variables.
- Give a workload access to a vault — Assign Secrets Reader on a vault to a workload's managed identity so that it can start with the vault's secrets.
- Use secrets in workloads — How apps, functions and container instances receive secrets from a vault when they start.
- Troubleshoot secret delivery — What to check when a workload does not start because of a secret, or starts without the value you expect.