Reference
External Secret Syncer
Overview
The External Secret Syncer is a marketplace application that can be used to continuously sync externally-stored secrets/parameters with Control Plane secrets. If you store your secrets externally, you can use this app to automatically keep Control Plane configuration options up to date.
Supported External Services
Setup
Prerequisies
- Have a secret/parameter set up in one of the external services supported
- Get an IAM account ready that allow read permissions for the desired secret
Steps
- Click the
ESS
application on the Console marketplace - Configure the options for your external secrets. See configuration
- (optional) Add cloud access to identity if available, instead of supplying keys in configuration.
Configuration
Vault KV engine secrets look like:
If you use parse
, make sure to start with data
to get the secret content
Secret
A secret generated by ESS will look like:
api
The ESS has a helpful utiliy api