Vaults
What a vault page shows, what its activity log records, and what deleting a vault does.
A vault holds secrets for the workloads in its boundary. Open Secret Vaults in the portal at https://portal.example.com and choose a vault to see its page.
The vault page
| Section | What it shows |
|---|---|
| Overview | Boundary, cluster, number of secrets, the protection settings and the Vault URI — the address clients such as the .NET client use |
| Configuration → Protection | Soft delete, retention period and purge protection |
| Secrets | The secrets in the vault — see Manage secrets |
| Access Control | Who can use the vault, including workloads — see Give a workload access |
| Revisions, Operations, Activity, Danger Zone | As on every resource |
Activity
The Activity tab records every change to a secret — set, delete, recover and purge — and every read of a value, with who read it, which version and through which route. Reads by the same principal of the same secret within five minutes are folded into one entry that counts them. A read that was refused is recorded too. Listing secrets and listing versions are not recorded.
Recording a read never delays or blocks it, so it is best effort: if the activity log cannot keep up or cannot be reached, the entry is written to the Secrets service's own log instead and does not appear in Activity.
Opening a secret's Edit sheet in the portal reads the current value, so it also appears as
a read. Viewing the activity log needs the kernel/activity/read permission.
Deleting a vault
Deleting a vault from its Danger Zone is permanent and immediate: every secret in it, including deleted ones, and the vault's encryption key are removed, and the vault's name becomes free for others to use. The vault's protection settings do not stop this.
A vault that was created for a container instance — named <instance>-secrets — is deleted
together with its instance.