Skip to content
Stackship documentation Svenska

SecretsUsers

Permissions

The actions that govern vaults and secrets, and the roles that hold them.

Actions

Action Allows
secretvault/read See vaults and the names of their secrets
secretvault/write Create and change vaults; includes secretvault/delete
secretvault/delete Delete vaults; also needed, with secretvault/writeSecrets, to delete and purge secrets
secretvault/readSecrets Reveal secret values and list versions
secretvault/writeSecrets Add, change, delete, recover and purge secrets

secretvault/readSecrets and secretvault/writeSecrets are data actions: a role only grants them when it lists them as such, so a role that can manage a vault does not by that alone read its values.

Roles

Role Vaults Secret values
Reader See No
Secrets Reader See Read
Secrets Writer See, create, change, delete Read and write
Contributor, Owner See, create, change, delete Read and write

Assign a role on a boundary, a resource group, or a single vault. Workloads need Secrets Reader — see Give a workload access.