Skip to content
Stackship documentation Svenska

SecretsUsers

Vaults

What a vault page shows, what its activity log records, and what deleting a vault does.

A vault holds secrets for the workloads in its boundary. Open Secret Vaults in the portal at https://portal.example.com and choose a vault to see its page.

The vault page

Section What it shows
Overview Boundary, cluster, number of secrets, the protection settings and the Vault URI — the address clients such as the .NET client use
Configuration → Protection Soft delete, retention period and purge protection
Secrets The secrets in the vault — see Manage secrets
Access Control Who can use the vault, including workloads — see Give a workload access
Revisions, Operations, Activity, Danger Zone As on every resource

Activity

The Activity tab records every change to a secret — set, delete, recover and purge — and every read of a value, with who read it, which version and through which route. Reads by the same principal of the same secret within five minutes are folded into one entry that counts them. A read that was refused is recorded too. Listing secrets and listing versions are not recorded.

Recording a read never delays or blocks it, so it is best effort: if the activity log cannot keep up or cannot be reached, the entry is written to the Secrets service's own log instead and does not appear in Activity.

Opening a secret's Edit sheet in the portal reads the current value, so it also appears as a read. Viewing the activity log needs the kernel/activity/read permission.

Deleting a vault

Deleting a vault from its Danger Zone is permanent and immediate: every secret in it, including deleted ones, and the vault's encryption key are removed, and the vault's name becomes free for others to use. The vault's protection settings do not stop this.

A vault that was created for a container instance — named <instance>-secrets — is deleted together with its instance.

Pages in this section