Names and limits
Naming rules for vaults and secrets, and the limits that apply to them.
Vault names
- Lowercase letters, digits and hyphens, not starting or ending with a hyphen.
- 3 to 50 characters in the portal; the API accepts up to 63.
- Unique across the whole platform. A deleted vault's name becomes free again.
- A vault created for a container instance is named
<instance>-secrets.
Secret names
- Letters, digits and hyphens, at most 127 characters.
- Unique among the vault's secrets that are not deleted.
- In a container instance, a vault secret is referenced by the same name.
Values and versions
- Every change creates a new version; all versions are kept.
- There is no limit on the number of secrets in a vault or versions of a secret.
- An expiry or not-before date is stored and shown, but does not stop delivery.
Deleted secrets
- A deleted secret can be purged 90 days after it was deleted, not before, and is never purged automatically.
- A vault's retention period (7 to 90 days) and purge protection are stored but not applied yet.