Skip to content
Stackship documentation Svenska

SecretsUsers

Create a vault

Create a vault in a resource group, choose its protection settings, and decide who can read it.

Requires: secretvault/write

Creating a vault needs the secretvault/write permission in the resource group; the Owner and Contributor roles have it.

Open the wizard

In the portal at https://portal.example.com, open Secret Vaults in the sidebar and choose Create Secret Vaults. The Create Secret Vault wizard has three steps.

Name and placement

The Basics step asks for:

  • Vault Name — lowercase letters, digits and hyphens, 3 to 50 characters, not starting or ending with a hyphen. The name is the vault's address, so it must be unique across the whole platform; a name that is already taken is refused when you create the vault.
  • Boundary, Cluster and Resource group — where the vault lives. Each is filled in for you when there is only one choice.

Protection settings

The Vault Configuration step sets how deleted secrets are to be protected:

  • Enable Soft Delete — on by default — with a Retention Period of 7 to 90 days (default 90).
  • Enable Purge Protection — off by default.

Important

These settings are stored on the vault but not applied yet. Every deleted secret is kept for 90 days whatever they say, and deleting the vault itself is always permanent. See Delete, recover and purge.

Review and create

Review & Create shows the name, resource group and protection settings. Create the vault; it is ready when its status is Ready, and its Overview then shows the Vault URI.

With the CLI:

bash
stsh vault create my-vault -g my-resource-group -c my-cluster

Anyone with Reader on its resource group or boundary can then look the vault up through the API:

http
GET https://api.example.com/boundaries/<boundary-id>/resourcegroups/my-resource-group/resources/secretvaults/my-vault

Who can read it

A new vault grants nobody anything new. People and workloads use it through roles assigned on its boundary, its resource group or the vault itself (Access Control):

  • Secrets Reader reads secret values.
  • Secrets Writer also creates, changes and deletes secrets.
  • Owner and Contributor can do both; Reader sees the vault and the names of its secrets, but no values.

A workload needs Secrets Reader on the vault before it can start with a secret from it — see Give a workload access. All roles and actions are listed in Permissions.

Next steps