A dictionary of key-values are stored under a given name.
Values can be stored directly (strings) or base64 encoded (binary values). Use base64 when the data contains characters that are not suitable for a string representation.
If a value is mounted as a file by the scheduler, then the decoded value will be used, ie base64 values will be unpacked.
Vaults storing versioned key/value secrets with optional metadata, retention policies, and access controls.
Created
Bad Request
Unauthorized
Forbidden
Not Found
Conflict (instance exists)
Service Unavailable (strongbox sealed)
name: some-vault max-versions: 1 cas-required: false delete-version-after: 0s distribute: sites: - stockholm-sergel - gotenburg-bergakungen
Vaults storing versioned key/value secrets with optional metadata, retention policies, and access controls.
| fields | string Retrieve only requested fields from the resource See section fields |
| where | string Retrieve only items matching the given expression. See section where |
| validate | string <enumeration> Validate the request but do not actually perform the requested operation |
| keys | string <enumeration> Retrieve only the keys for the list |
| count | string <enumeration> Retrieve only the number of elements in the list |
OK
Bad Request
Unauthorized
Forbidden
Not Found
Precondition Failed
Service Unavailable (strongbox sealed)
- name: some-vault max-versions: 1 cas-required: false delete-version-after: 0s distribute: sites: - stockholm-sergel - gotenburg-bergakungen
Vaults storing versioned key/value secrets with optional metadata, retention policies, and access controls.
No Content
Bad Request
Unauthorized
Forbidden
Not Found
Precondition Failed
Service Unavailable (strongbox sealed)
name: some-vault max-versions: 1 cas-required: false delete-version-after: 0s distribute: sites: - stockholm-sergel - gotenburg-bergakungen
Vaults storing versioned key/value secrets with optional metadata, retention policies, and access controls.
No Content
Bad Request
Unauthorized
Forbidden
Not Found
Precondition Failed
Service Unavailable (strongbox sealed)
Vaults storing versioned key/value secrets with optional metadata, retention policies, and access controls.
Created
No Content
Bad Request
Unauthorized
Forbidden
Not Found
Precondition Failed
Service Unavailable (strongbox sealed)
name: some-vault max-versions: 1 cas-required: false delete-version-after: 0s distribute: sites: - stockholm-sergel - gotenburg-bergakungen
Vaults storing versioned key/value secrets with optional metadata, retention policies, and access controls.
| fields | string Retrieve only requested fields from the resource See section fields |
| where | string Retrieve only items matching the given expression. See section where |
| validate | string <enumeration> Validate the request but do not actually perform the requested operation |
| version-list | string <enumeration> Retrieve list of old versions |
| version | string Retrieve requested old version of the resource |
OK
Bad Request
Unauthorized
Forbidden
Not Found
Precondition Failed
Service Unavailable (strongbox sealed)
name: some-vault max-versions: 1 cas-required: false delete-version-after: 0s distribute: sites: - stockholm-sergel - gotenburg-bergakungen
Versioned secrets within a vault. Each entry holds the current and historical secret data and metadata.
Created
Bad Request
Unauthorized
Forbidden
Not Found
Conflict (instance exists)
Service Unavailable (strongbox sealed)
name: credentials base64-data: xx: eXk= yy: aGVg data: password: reallysecret user: admin auto-cert: issuing-ca: root refresh-threshold: 10d ttl: 20d align-to-midnight: true truncate-ttl: false host: www.server.com public-key: | -----BEGIN PUBLIC KEY----- MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAECMA6yO9x3I3qSjbEZ7nWlAFF/aiA puUfIlWEHcTwgiFvCdvV4rnXzdoSxZh5B6oK6KEDA4hqCV9Re8bIQ8VLlA== -----END PUBLIC KEY----- cert-type: server alt-name: - type: DNSName value: www.server.com server-ext-usage: true client-ext-usage: true code-signing-ext-usage: true full-authority-key-identifier: false serial-prefix: fe:ed:ba:be auto-ssh-cert: issuing-ca: root issuing-role: admin public-key: ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAIEAstFt4AUzsP1iEC9a4tO2G3ISbTSSthvUvWYoq0yWy0dzbnditXgw5rVBTuIC1oltNuAdsol+lOBbZLS2ZE6rDCeAq82AYu3EsdVBiHsZMocEjgg45xxd8+0tzaVZjevQWo9gkIqMesHEYgUGiwFZF4747AILemSwKz+X6HD78fs= joe@acme.com refresh-threshold: 10d ttl: 15d valid-principals: - joe cert-type: user key-id: joe critical-options: - force-command extensions: - permit-X11-forwarding - permit-agent-forwarding - permit-pty auto-acme-cert: acme-service: pebble refresh-threshold: 30d names: - foo.site.test wait: 1m allow-image-access: - "*" allow-application-access: - popcorn-controller.popcorn-controller-service.kettle-popper-manager allow-tenant-access: - acme ttl: 4h
Versioned secrets within a vault. Each entry holds the current and historical secret data and metadata.
| fields | string Retrieve only requested fields from the resource See section fields |
| where | string Retrieve only items matching the given expression. See section where |
| validate | string <enumeration> Validate the request but do not actually perform the requested operation |
| keys | string <enumeration> Retrieve only the keys for the list |
| count | string <enumeration> Retrieve only the number of elements in the list |
OK
Bad Request
Unauthorized
Forbidden
Not Found
Precondition Failed
Service Unavailable (strongbox sealed)
- name: credentials base64-data: xx: eXk= yy: aGVg data: password: reallysecret user: admin auto-cert: issuing-ca: root refresh-threshold: 10d ttl: 20d align-to-midnight: true truncate-ttl: false host: www.server.com public-key: | -----BEGIN PUBLIC KEY----- MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAECMA6yO9x3I3qSjbEZ7nWlAFF/aiA puUfIlWEHcTwgiFvCdvV4rnXzdoSxZh5B6oK6KEDA4hqCV9Re8bIQ8VLlA== -----END PUBLIC KEY----- cert-type: server alt-name: - type: DNSName value: www.server.com server-ext-usage: true client-ext-usage: true code-signing-ext-usage: true full-authority-key-identifier: false serial-prefix: fe:ed:ba:be auto-ssh-cert: issuing-ca: root issuing-role: admin public-key: ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAIEAstFt4AUzsP1iEC9a4tO2G3ISbTSSthvUvWYoq0yWy0dzbnditXgw5rVBTuIC1oltNuAdsol+lOBbZLS2ZE6rDCeAq82AYu3EsdVBiHsZMocEjgg45xxd8+0tzaVZjevQWo9gkIqMesHEYgUGiwFZF4747AILemSwKz+X6HD78fs= joe@acme.com refresh-threshold: 10d ttl: 15d valid-principals: - joe cert-type: user key-id: joe critical-options: - force-command extensions: - permit-X11-forwarding - permit-agent-forwarding - permit-pty auto-acme-cert: acme-service: pebble refresh-threshold: 30d names: - foo.site.test wait: 1m allow-image-access: - "*" allow-application-access: - popcorn-controller.popcorn-controller-service.kettle-popper-manager allow-tenant-access: - acme ttl: 4h
Versioned secrets within a vault. Each entry holds the current and historical secret data and metadata.
No Content
Bad Request
Unauthorized
Forbidden
Not Found
Precondition Failed
Service Unavailable (strongbox sealed)
name: credentials base64-data: xx: eXk= yy: aGVg data: password: reallysecret user: admin auto-cert: issuing-ca: root refresh-threshold: 10d ttl: 20d align-to-midnight: true truncate-ttl: false host: www.server.com public-key: | -----BEGIN PUBLIC KEY----- MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAECMA6yO9x3I3qSjbEZ7nWlAFF/aiA puUfIlWEHcTwgiFvCdvV4rnXzdoSxZh5B6oK6KEDA4hqCV9Re8bIQ8VLlA== -----END PUBLIC KEY----- cert-type: server alt-name: - type: DNSName value: www.server.com server-ext-usage: true client-ext-usage: true code-signing-ext-usage: true full-authority-key-identifier: false serial-prefix: fe:ed:ba:be auto-ssh-cert: issuing-ca: root issuing-role: admin public-key: ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAIEAstFt4AUzsP1iEC9a4tO2G3ISbTSSthvUvWYoq0yWy0dzbnditXgw5rVBTuIC1oltNuAdsol+lOBbZLS2ZE6rDCeAq82AYu3EsdVBiHsZMocEjgg45xxd8+0tzaVZjevQWo9gkIqMesHEYgUGiwFZF4747AILemSwKz+X6HD78fs= joe@acme.com refresh-threshold: 10d ttl: 15d valid-principals: - joe cert-type: user key-id: joe critical-options: - force-command extensions: - permit-X11-forwarding - permit-agent-forwarding - permit-pty auto-acme-cert: acme-service: pebble refresh-threshold: 30d names: - foo.site.test wait: 1m allow-image-access: - "*" allow-application-access: - popcorn-controller.popcorn-controller-service.kettle-popper-manager allow-tenant-access: - acme ttl: 4h
Versioned secrets within a vault. Each entry holds the current and historical secret data and metadata.
No Content
Bad Request
Unauthorized
Forbidden
Not Found
Precondition Failed
Service Unavailable (strongbox sealed)
Versioned secrets within a vault. Each entry holds the current and historical secret data and metadata.
Created
No Content
Bad Request
Unauthorized
Forbidden
Not Found
Precondition Failed
Service Unavailable (strongbox sealed)
name: credentials base64-data: xx: eXk= yy: aGVg data: password: reallysecret user: admin auto-cert: issuing-ca: root refresh-threshold: 10d ttl: 20d align-to-midnight: true truncate-ttl: false host: www.server.com public-key: | -----BEGIN PUBLIC KEY----- MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAECMA6yO9x3I3qSjbEZ7nWlAFF/aiA puUfIlWEHcTwgiFvCdvV4rnXzdoSxZh5B6oK6KEDA4hqCV9Re8bIQ8VLlA== -----END PUBLIC KEY----- cert-type: server alt-name: - type: DNSName value: www.server.com server-ext-usage: true client-ext-usage: true code-signing-ext-usage: true full-authority-key-identifier: false serial-prefix: fe:ed:ba:be auto-ssh-cert: issuing-ca: root issuing-role: admin public-key: ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAIEAstFt4AUzsP1iEC9a4tO2G3ISbTSSthvUvWYoq0yWy0dzbnditXgw5rVBTuIC1oltNuAdsol+lOBbZLS2ZE6rDCeAq82AYu3EsdVBiHsZMocEjgg45xxd8+0tzaVZjevQWo9gkIqMesHEYgUGiwFZF4747AILemSwKz+X6HD78fs= joe@acme.com refresh-threshold: 10d ttl: 15d valid-principals: - joe cert-type: user key-id: joe critical-options: - force-command extensions: - permit-X11-forwarding - permit-agent-forwarding - permit-pty auto-acme-cert: acme-service: pebble refresh-threshold: 30d names: - foo.site.test wait: 1m allow-image-access: - "*" allow-application-access: - popcorn-controller.popcorn-controller-service.kettle-popper-manager allow-tenant-access: - acme ttl: 4h
Versioned secrets within a vault. Each entry holds the current and historical secret data and metadata.
| fields | string Retrieve only requested fields from the resource See section fields |
| where | string Retrieve only items matching the given expression. See section where |
| validate | string <enumeration> Validate the request but do not actually perform the requested operation |
| version-list | string <enumeration> Retrieve list of old versions |
| version | string Retrieve requested old version of the resource |
OK
Bad Request
Unauthorized
Forbidden
Not Found
Precondition Failed
Service Unavailable (strongbox sealed)
name: credentials base64-data: xx: eXk= yy: aGVg data: password: reallysecret user: admin auto-cert: issuing-ca: root refresh-threshold: 10d ttl: 20d align-to-midnight: true truncate-ttl: false host: www.server.com public-key: | -----BEGIN PUBLIC KEY----- MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAECMA6yO9x3I3qSjbEZ7nWlAFF/aiA puUfIlWEHcTwgiFvCdvV4rnXzdoSxZh5B6oK6KEDA4hqCV9Re8bIQ8VLlA== -----END PUBLIC KEY----- cert-type: server alt-name: - type: DNSName value: www.server.com server-ext-usage: true client-ext-usage: true code-signing-ext-usage: true full-authority-key-identifier: false serial-prefix: fe:ed:ba:be auto-ssh-cert: issuing-ca: root issuing-role: admin public-key: ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAIEAstFt4AUzsP1iEC9a4tO2G3ISbTSSthvUvWYoq0yWy0dzbnditXgw5rVBTuIC1oltNuAdsol+lOBbZLS2ZE6rDCeAq82AYu3EsdVBiHsZMocEjgg45xxd8+0tzaVZjevQWo9gkIqMesHEYgUGiwFZF4747AILemSwKz+X6HD78fs= joe@acme.com refresh-threshold: 10d ttl: 15d valid-principals: - joe cert-type: user key-id: joe critical-options: - force-command extensions: - permit-X11-forwarding - permit-agent-forwarding - permit-pty auto-acme-cert: acme-service: pebble refresh-threshold: 30d names: - foo.site.test wait: 1m allow-image-access: - "*" allow-application-access: - popcorn-controller.popcorn-controller-service.kettle-popper-manager allow-tenant-access: - acme ttl: 4h
Vaults storing versioned key/value secrets with optional metadata, retention policies, and access controls.
| fields | string Retrieve only requested fields from the resource See section fields |
| where | string Retrieve only items matching the given expression. See section where |
| site | string Send the request to the specfifed site |
| content | string <enumeration> Filter descendant nodes in the response |
| keys | string <enumeration> Retrieve only the keys for the list |
| count | string <enumeration> Retrieve only the number of elements in the list |
OK
Bad Request
Unauthorized
Forbidden
Not Found
Service Unavailable (strongbox sealed)
- name: some-vault max-versions: 1 cas-required: false delete-version-after: 0s distribute: sites: - stockholm-sergel - gotenburg-bergakungen distribution-status: sites: - stockholm-sergel - gotenburg-bergakungen
Vaults storing versioned key/value secrets with optional metadata, retention policies, and access controls.
| fields | string Retrieve only requested fields from the resource See section fields |
| where | string Retrieve only items matching the given expression. See section where |
| site | string Send the request to the specfifed site |
| content | string <enumeration> Filter descendant nodes in the response |
OK
Bad Request
Unauthorized
Forbidden
Not Found
Service Unavailable (strongbox sealed)
name: some-vault max-versions: 1 cas-required: false delete-version-after: 0s distribute: sites: - stockholm-sergel - gotenburg-bergakungen distribution-status: sites: - stockholm-sergel - gotenburg-bergakungen
Versioned secrets within a vault. Each entry holds the current and historical secret data and metadata.
| fields | string Retrieve only requested fields from the resource See section fields |
| where | string Retrieve only items matching the given expression. See section where |
| site | string Send the request to the specfifed site |
| content | string <enumeration> Filter descendant nodes in the response |
| keys | string <enumeration> Retrieve only the keys for the list |
| count | string <enumeration> Retrieve only the number of elements in the list |
OK
Bad Request
Unauthorized
Forbidden
Not Found
Service Unavailable (strongbox sealed)
- name: credentials base64-data: xx: eXk= yy: aGVg data: password: reallysecret user: admin auto-cert: issuing-ca: root refresh-threshold: 10d ttl: 20d align-to-midnight: true truncate-ttl: false host: www.server.com public-key: | -----BEGIN PUBLIC KEY----- MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAECMA6yO9x3I3qSjbEZ7nWlAFF/aiA puUfIlWEHcTwgiFvCdvV4rnXzdoSxZh5B6oK6KEDA4hqCV9Re8bIQ8VLlA== -----END PUBLIC KEY----- cert-type: server alt-name: - type: DNSName value: www.server.com server-ext-usage: true client-ext-usage: true code-signing-ext-usage: true full-authority-key-identifier: false serial-prefix: fe:ed:ba:be cert: cert.pem: | -----BEGIN CERTIFICATE----- MIICeTCCAiCgAwIBAgITAJoov8FFieL9BHIIv+WenC4f8jAKBggqhkjOPQQDAjBa MQ8wDQYDVQQDEwZBdmFzc2ExEjAQBgNVBAcTCVN0b2NraG9sbTELMAkGA1UEBhMC U0UxDzANBgNVBAoTBkF2YXNzYTEVMBMGA1UECxMMZGlzdHJpYnV0aW9uMCIYDzIw MjIwMTEyMTEwMzM2WhgPMjAyMjAyMDExNTUxMzZaMGIxFzAVBgNVBAMTDnd3dy5z ZXJ2ZXIuY29tMRIwEAYDVQQHEwlTdG9ja2hvbG0xCzAJBgNVBAYTAlNFMQ8wDQYD VQQKEwZBdmFzc2ExFTATBgNVBAsTDGRpc3RyaWJ1dGlvbjBZMBMGByqGSM49AgEG CCqGSM49AwEHA0IABGVqGAt14O1helv02eAi3510lAoMNnyQCYl+fj+AI0aj2OqJ 2pfACv+1D/8SS0EeBNOpuyK31wJUBMAvfbNVsMWjgbgwgbUwfQYDVR0jBHYwdKFe pFwwWjEPMA0GA1UEAxMGQXZhc3NhMRIwEAYDVQQHEwlTdG9ja2hvbG0xCzAJBgNV BAYTAlNFMQ8wDQYDVQQKEwZBdmFzc2ExFTATBgNVBAsTDGRpc3RyaWJ1dGlvboIS LL8LSoDJCZYPbe4M+XG6StKZMBkGA1UdEQQSMBCCDnd3dy5zZXJ2ZXIuY29tMAsG A1UdDwQEAwIDiDAMBgNVHRMBAf8EAjAAMAoGCCqGSM49BAMCA0cAMEQCIAqAfJK+ 8Duk8Qrj55YwkuRyt97Cv4/bbIpRwaNJxafIAiAn7GO/fkOjhWZCYfB8yx92Kl3Y Tl0y+hIVaLkKoXuMhg== -----END CERTIFICATE----- cert.key: | -----BEGIN EC PRIVATE KEY----- MHcCAQEEIOtZk70H7MTVQOPOJFQPVzM0Kjc0B8wXj7OtrjtyBYVLoAoGCCqGSM49 AwEHoUQDQgAEZWoYC3Xg7WF6W/TZ4CLfnXSUCgw2fJAJiX5+P4AjRqPY6onal8AK /7UP/xJLQR4E06m7IrfXAlQEwC99s1WwxQ== -----END EC PRIVATE KEY----- ca-cert.pem: | -----BEGIN CERTIFICATE----- MIICAzCCAaqgAwIBAgISLL8LSoDJCZYPbe4M+XG6StKZMAoGCCqGSM49BAMCMFox DzANBgNVBAMTBkF2YXNzYTESMBAGA1UEBxMJU3RvY2tob2xtMQswCQYDVQQGEwJT RTEPMA0GA1UEChMGQXZhc3NhMRUwEwYDVQQLEwxkaXN0cmlidXRpb24wIhgPMjAy MjAxMDkwMDEzMDZaGA8yMDIzMDExMjE1NDkwNlowWjEPMA0GA1UEAxMGQXZhc3Nh MRIwEAYDVQQHEwlTdG9ja2hvbG0xCzAJBgNVBAYTAlNFMQ8wDQYDVQQKEwZBdmFz c2ExFTATBgNVBAsTDGRpc3RyaWJ1dGlvbjBZMBMGByqGSM49AgEGCCqGSM49AwEH A0IABAjAOsjvcdyN6ko2xGe51pQBRf2ogKblHyJVhB3E8IIhbwnb1eK5183aEsWY eQeqCuihAwOIaglfUXvGyEPFS5SjTDBKMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMB Af8EBTADAQH/MCcGA1UdHwQgMB4wHKAaoBiGFmh0dHA6Ly9jcmwuYXZhc3NhLm5l dC8wCgYIKoZIzj0EAwIDRwAwRAIgGMkKpCKX1zpsdKY7SuB2sPvM1i1eAJtR10PE /x29sRsCIF/jigjXX52APfotfWAhRmcd3Cp1D1/oKai03cnSM/K8 -----END CERTIFICATE----- auto-ssh-cert: issuing-ca: root issuing-role: admin public-key: ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAIEAstFt4AUzsP1iEC9a4tO2G3ISbTSSthvUvWYoq0yWy0dzbnditXgw5rVBTuIC1oltNuAdsol+lOBbZLS2ZE6rDCeAq82AYu3EsdVBiHsZMocEjgg45xxd8+0tzaVZjevQWo9gkIqMesHEYgUGiwFZF4747AILemSwKz+X6HD78fs= joe@acme.com refresh-threshold: 10d ttl: 15d valid-principals: - joe cert-type: user key-id: joe critical-options: - force-command extensions: - permit-X11-forwarding - permit-agent-forwarding - permit-pty auto-acme-cert: acme-service: pebble refresh-threshold: 30d names: - foo.site.test wait: 1m dict: xx: eXk= cert.pem: | -----BEGIN CERTIFICATE----- MIICeTCCAiCgAwIBAgITAJoov8FFieL9BHIIv+WenC4f8jAKBggqhkjOPQQDAjBa MQ8wDQYDVQQDEwZBdmFzc2ExEjAQBgNVBAcTCVN0b2NraG9sbTELMAkGA1UEBhMC U0UxDzANBgNVBAoTBkF2YXNzYTEVMBMGA1UECxMMZGlzdHJpYnV0aW9uMCIYDzIw MjIwMTEyMTEwMzM2WhgPMjAyMjAyMDExNTUxMzZaMGIxFzAVBgNVBAMTDnd3dy5z ZXJ2ZXIuY29tMRIwEAYDVQQHEwlTdG9ja2hvbG0xCzAJBgNVBAYTAlNFMQ8wDQYD VQQKEwZBdmFzc2ExFTATBgNVBAsTDGRpc3RyaWJ1dGlvbjBZMBMGByqGSM49AgEG CCqGSM49AwEHA0IABGVqGAt14O1helv02eAi3510lAoMNnyQCYl+fj+AI0aj2OqJ 2pfACv+1D/8SS0EeBNOpuyK31wJUBMAvfbNVsMWjgbgwgbUwfQYDVR0jBHYwdKFe pFwwWjEPMA0GA1UEAxMGQXZhc3NhMRIwEAYDVQQHEwlTdG9ja2hvbG0xCzAJBgNV BAYTAlNFMQ8wDQYDVQQKEwZBdmFzc2ExFTATBgNVBAsTDGRpc3RyaWJ1dGlvboIS LL8LSoDJCZYPbe4M+XG6StKZMBkGA1UdEQQSMBCCDnd3dy5zZXJ2ZXIuY29tMAsG A1UdDwQEAwIDiDAMBgNVHRMBAf8EAjAAMAoGCCqGSM49BAMCA0cAMEQCIAqAfJK+ 8Duk8Qrj55YwkuRyt97Cv4/bbIpRwaNJxafIAiAn7GO/fkOjhWZCYfB8yx92Kl3Y Tl0y+hIVaLkKoXuMhg== -----END CERTIFICATE----- cert.key: | -----BEGIN EC PRIVATE KEY----- MHcCAQEEIOtZk70H7MTVQOPOJFQPVzM0Kjc0B8wXj7OtrjtyBYVLoAoGCCqGSM49 AwEHoUQDQgAEZWoYC3Xg7WF6W/TZ4CLfnXSUCgw2fJAJiX5+P4AjRqPY6onal8AK /7UP/xJLQR4E06m7IrfXAlQEwC99s1WwxQ== -----END EC PRIVATE KEY----- ca-cert.pem: | -----BEGIN CERTIFICATE----- MIICAzCCAaqgAwIBAgISLL8LSoDJCZYPbe4M+XG6StKZMAoGCCqGSM49BAMCMFox DzANBgNVBAMTBkF2YXNzYTESMBAGA1UEBxMJU3RvY2tob2xtMQswCQYDVQQGEwJT RTEPMA0GA1UEChMGQXZhc3NhMRUwEwYDVQQLEwxkaXN0cmlidXRpb24wIhgPMjAy MjAxMDkwMDEzMDZaGA8yMDIzMDExMjE1NDkwNlowWjEPMA0GA1UEAxMGQXZhc3Nh MRIwEAYDVQQHEwlTdG9ja2hvbG0xCzAJBgNVBAYTAlNFMQ8wDQYDVQQKEwZBdmFz c2ExFTATBgNVBAsTDGRpc3RyaWJ1dGlvbjBZMBMGByqGSM49AgEGCCqGSM49AwEH A0IABAjAOsjvcdyN6ko2xGe51pQBRf2ogKblHyJVhB3E8IIhbwnb1eK5183aEsWY eQeqCuihAwOIaglfUXvGyEPFS5SjTDBKMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMB Af8EBTADAQH/MCcGA1UdHwQgMB4wHKAaoBiGFmh0dHA6Ly9jcmwuYXZhc3NhLm5l dC8wCgYIKoZIzj0EAwIDRwAwRAIgGMkKpCKX1zpsdKY7SuB2sPvM1i1eAJtR10PE /x29sRsCIF/jigjXX52APfotfWAhRmcd3Cp1D1/oKai03cnSM/K8 -----END CERTIFICATE----- password: reallysecret yy: aGVg user: admin allow-image-access: - "*" allow-application-access: - popcorn-controller.popcorn-controller-service.kettle-popper-manager allow-tenant-access: - acme creation-time: 2022-01-12T14:56:10.018462Z deletion-time: 2022-01-12T14:56:10.018462Z destroyed: false cert-refresh-time: 2022-01-13T01:51:34.308328Z version: 1 metadata: current-version: 1 modified-time: 2022-01-12T14:56:10.018463Z creation-time: 2022-01-12T14:56:10.018462Z oldest-version: 1 ttl: 4h error: tls CA does not exist
Versioned secrets within a vault. Each entry holds the current and historical secret data and metadata.
| fields | string Retrieve only requested fields from the resource See section fields |
| where | string Retrieve only items matching the given expression. See section where |
| site | string Send the request to the specfifed site |
| content | string <enumeration> Filter descendant nodes in the response |
OK
Bad Request
Unauthorized
Forbidden
Not Found
Service Unavailable (strongbox sealed)
name: credentials base64-data: xx: eXk= yy: aGVg data: password: reallysecret user: admin auto-cert: issuing-ca: root refresh-threshold: 10d ttl: 20d align-to-midnight: true truncate-ttl: false host: www.server.com public-key: | -----BEGIN PUBLIC KEY----- MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAECMA6yO9x3I3qSjbEZ7nWlAFF/aiA puUfIlWEHcTwgiFvCdvV4rnXzdoSxZh5B6oK6KEDA4hqCV9Re8bIQ8VLlA== -----END PUBLIC KEY----- cert-type: server alt-name: - type: DNSName value: www.server.com server-ext-usage: true client-ext-usage: true code-signing-ext-usage: true full-authority-key-identifier: false serial-prefix: fe:ed:ba:be cert: cert.pem: | -----BEGIN CERTIFICATE----- MIICeTCCAiCgAwIBAgITAJoov8FFieL9BHIIv+WenC4f8jAKBggqhkjOPQQDAjBa MQ8wDQYDVQQDEwZBdmFzc2ExEjAQBgNVBAcTCVN0b2NraG9sbTELMAkGA1UEBhMC U0UxDzANBgNVBAoTBkF2YXNzYTEVMBMGA1UECxMMZGlzdHJpYnV0aW9uMCIYDzIw MjIwMTEyMTEwMzM2WhgPMjAyMjAyMDExNTUxMzZaMGIxFzAVBgNVBAMTDnd3dy5z ZXJ2ZXIuY29tMRIwEAYDVQQHEwlTdG9ja2hvbG0xCzAJBgNVBAYTAlNFMQ8wDQYD VQQKEwZBdmFzc2ExFTATBgNVBAsTDGRpc3RyaWJ1dGlvbjBZMBMGByqGSM49AgEG CCqGSM49AwEHA0IABGVqGAt14O1helv02eAi3510lAoMNnyQCYl+fj+AI0aj2OqJ 2pfACv+1D/8SS0EeBNOpuyK31wJUBMAvfbNVsMWjgbgwgbUwfQYDVR0jBHYwdKFe pFwwWjEPMA0GA1UEAxMGQXZhc3NhMRIwEAYDVQQHEwlTdG9ja2hvbG0xCzAJBgNV BAYTAlNFMQ8wDQYDVQQKEwZBdmFzc2ExFTATBgNVBAsTDGRpc3RyaWJ1dGlvboIS LL8LSoDJCZYPbe4M+XG6StKZMBkGA1UdEQQSMBCCDnd3dy5zZXJ2ZXIuY29tMAsG A1UdDwQEAwIDiDAMBgNVHRMBAf8EAjAAMAoGCCqGSM49BAMCA0cAMEQCIAqAfJK+ 8Duk8Qrj55YwkuRyt97Cv4/bbIpRwaNJxafIAiAn7GO/fkOjhWZCYfB8yx92Kl3Y Tl0y+hIVaLkKoXuMhg== -----END CERTIFICATE----- cert.key: | -----BEGIN EC PRIVATE KEY----- MHcCAQEEIOtZk70H7MTVQOPOJFQPVzM0Kjc0B8wXj7OtrjtyBYVLoAoGCCqGSM49 AwEHoUQDQgAEZWoYC3Xg7WF6W/TZ4CLfnXSUCgw2fJAJiX5+P4AjRqPY6onal8AK /7UP/xJLQR4E06m7IrfXAlQEwC99s1WwxQ== -----END EC PRIVATE KEY----- ca-cert.pem: | -----BEGIN CERTIFICATE----- MIICAzCCAaqgAwIBAgISLL8LSoDJCZYPbe4M+XG6StKZMAoGCCqGSM49BAMCMFox DzANBgNVBAMTBkF2YXNzYTESMBAGA1UEBxMJU3RvY2tob2xtMQswCQYDVQQGEwJT RTEPMA0GA1UEChMGQXZhc3NhMRUwEwYDVQQLEwxkaXN0cmlidXRpb24wIhgPMjAy MjAxMDkwMDEzMDZaGA8yMDIzMDExMjE1NDkwNlowWjEPMA0GA1UEAxMGQXZhc3Nh MRIwEAYDVQQHEwlTdG9ja2hvbG0xCzAJBgNVBAYTAlNFMQ8wDQYDVQQKEwZBdmFz c2ExFTATBgNVBAsTDGRpc3RyaWJ1dGlvbjBZMBMGByqGSM49AgEGCCqGSM49AwEH A0IABAjAOsjvcdyN6ko2xGe51pQBRf2ogKblHyJVhB3E8IIhbwnb1eK5183aEsWY eQeqCuihAwOIaglfUXvGyEPFS5SjTDBKMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMB Af8EBTADAQH/MCcGA1UdHwQgMB4wHKAaoBiGFmh0dHA6Ly9jcmwuYXZhc3NhLm5l dC8wCgYIKoZIzj0EAwIDRwAwRAIgGMkKpCKX1zpsdKY7SuB2sPvM1i1eAJtR10PE /x29sRsCIF/jigjXX52APfotfWAhRmcd3Cp1D1/oKai03cnSM/K8 -----END CERTIFICATE----- auto-ssh-cert: issuing-ca: root issuing-role: admin public-key: ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAIEAstFt4AUzsP1iEC9a4tO2G3ISbTSSthvUvWYoq0yWy0dzbnditXgw5rVBTuIC1oltNuAdsol+lOBbZLS2ZE6rDCeAq82AYu3EsdVBiHsZMocEjgg45xxd8+0tzaVZjevQWo9gkIqMesHEYgUGiwFZF4747AILemSwKz+X6HD78fs= joe@acme.com refresh-threshold: 10d ttl: 15d valid-principals: - joe cert-type: user key-id: joe critical-options: - force-command extensions: - permit-X11-forwarding - permit-agent-forwarding - permit-pty auto-acme-cert: acme-service: pebble refresh-threshold: 30d names: - foo.site.test wait: 1m dict: xx: eXk= cert.pem: | -----BEGIN CERTIFICATE----- MIICeTCCAiCgAwIBAgITAJoov8FFieL9BHIIv+WenC4f8jAKBggqhkjOPQQDAjBa MQ8wDQYDVQQDEwZBdmFzc2ExEjAQBgNVBAcTCVN0b2NraG9sbTELMAkGA1UEBhMC U0UxDzANBgNVBAoTBkF2YXNzYTEVMBMGA1UECxMMZGlzdHJpYnV0aW9uMCIYDzIw MjIwMTEyMTEwMzM2WhgPMjAyMjAyMDExNTUxMzZaMGIxFzAVBgNVBAMTDnd3dy5z ZXJ2ZXIuY29tMRIwEAYDVQQHEwlTdG9ja2hvbG0xCzAJBgNVBAYTAlNFMQ8wDQYD VQQKEwZBdmFzc2ExFTATBgNVBAsTDGRpc3RyaWJ1dGlvbjBZMBMGByqGSM49AgEG CCqGSM49AwEHA0IABGVqGAt14O1helv02eAi3510lAoMNnyQCYl+fj+AI0aj2OqJ 2pfACv+1D/8SS0EeBNOpuyK31wJUBMAvfbNVsMWjgbgwgbUwfQYDVR0jBHYwdKFe pFwwWjEPMA0GA1UEAxMGQXZhc3NhMRIwEAYDVQQHEwlTdG9ja2hvbG0xCzAJBgNV BAYTAlNFMQ8wDQYDVQQKEwZBdmFzc2ExFTATBgNVBAsTDGRpc3RyaWJ1dGlvboIS LL8LSoDJCZYPbe4M+XG6StKZMBkGA1UdEQQSMBCCDnd3dy5zZXJ2ZXIuY29tMAsG A1UdDwQEAwIDiDAMBgNVHRMBAf8EAjAAMAoGCCqGSM49BAMCA0cAMEQCIAqAfJK+ 8Duk8Qrj55YwkuRyt97Cv4/bbIpRwaNJxafIAiAn7GO/fkOjhWZCYfB8yx92Kl3Y Tl0y+hIVaLkKoXuMhg== -----END CERTIFICATE----- cert.key: | -----BEGIN EC PRIVATE KEY----- MHcCAQEEIOtZk70H7MTVQOPOJFQPVzM0Kjc0B8wXj7OtrjtyBYVLoAoGCCqGSM49 AwEHoUQDQgAEZWoYC3Xg7WF6W/TZ4CLfnXSUCgw2fJAJiX5+P4AjRqPY6onal8AK /7UP/xJLQR4E06m7IrfXAlQEwC99s1WwxQ== -----END EC PRIVATE KEY----- ca-cert.pem: | -----BEGIN CERTIFICATE----- MIICAzCCAaqgAwIBAgISLL8LSoDJCZYPbe4M+XG6StKZMAoGCCqGSM49BAMCMFox DzANBgNVBAMTBkF2YXNzYTESMBAGA1UEBxMJU3RvY2tob2xtMQswCQYDVQQGEwJT RTEPMA0GA1UEChMGQXZhc3NhMRUwEwYDVQQLEwxkaXN0cmlidXRpb24wIhgPMjAy MjAxMDkwMDEzMDZaGA8yMDIzMDExMjE1NDkwNlowWjEPMA0GA1UEAxMGQXZhc3Nh MRIwEAYDVQQHEwlTdG9ja2hvbG0xCzAJBgNVBAYTAlNFMQ8wDQYDVQQKEwZBdmFz c2ExFTATBgNVBAsTDGRpc3RyaWJ1dGlvbjBZMBMGByqGSM49AgEGCCqGSM49AwEH A0IABAjAOsjvcdyN6ko2xGe51pQBRf2ogKblHyJVhB3E8IIhbwnb1eK5183aEsWY eQeqCuihAwOIaglfUXvGyEPFS5SjTDBKMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMB Af8EBTADAQH/MCcGA1UdHwQgMB4wHKAaoBiGFmh0dHA6Ly9jcmwuYXZhc3NhLm5l dC8wCgYIKoZIzj0EAwIDRwAwRAIgGMkKpCKX1zpsdKY7SuB2sPvM1i1eAJtR10PE /x29sRsCIF/jigjXX52APfotfWAhRmcd3Cp1D1/oKai03cnSM/K8 -----END CERTIFICATE----- password: reallysecret yy: aGVg user: admin allow-image-access: - "*" allow-application-access: - popcorn-controller.popcorn-controller-service.kettle-popper-manager allow-tenant-access: - acme creation-time: 2022-01-12T14:56:10.018462Z deletion-time: 2022-01-12T14:56:10.018462Z destroyed: false cert-refresh-time: 2022-01-13T01:51:34.308328Z version: 1 metadata: current-version: 1 modified-time: 2022-01-12T14:56:10.018463Z creation-time: 2022-01-12T14:56:10.018462Z oldest-version: 1 ttl: 4h error: tls CA does not exist
Deletes one or more versions of a secret. The version can later be
un-deleted using the undelete operation.
No Content
Bad Request
Unauthorized
Forbidden
Not Found
Service Unavailable (strongbox sealed)
versions: - 1
Completely removes one or more versions of a secret. When the last version is removed, the entire secret is removed.
No Content
Bad Request
Unauthorized
Forbidden
Not Found
Service Unavailable (strongbox sealed)
versions: - 1
Restores one or more versions of a secret.
No Content
Bad Request
Unauthorized
Forbidden
Not Found
Service Unavailable (strongbox sealed)
versions: - 1