Orkestia
Blog
Vault

Reference

Every vault.* workflow with the permission it needs, error codes, limits and troubleshooting

Workflows

Each workflow acts on your current organization.

WorkflowNeedsDoes
vault.secret.writewriteStore a new version
vault.secret.readreadReveal the value once to the person who asked
vault.secret.resolveresolvePass the value to a workflow step without showing it
vault.http.requestuseCall an API with the secret; get the response without it
vault.secret.usage.setowner or adminTurn API access on or off for a secret
vault.secret.listlistSecrets you can see, no values
vault.secret.metadata.getlistOne secret's versions and settings
vault.secret.deletedeleteHide versions
vault.secret.undeletedeleteRestore hidden versions
vault.secret.destroydestroyErase versions for good
vault.secret.metadata.deletedestroyRemove a secret and all its versions
vault.policy.set / list / deleteadminManage policies
vault.audit.listadminRead the audit log
vault.key.rotateadminRotate the organization's key

Owners and admins have every permission. See Access policies.

Errors

CodeMeans
VAULT_ACCESS_DENIEDYou don't have permission for this. The audit log shows why
VAULT_NOT_FOUNDNo secret at that path, or no such version
VAULT_CONFLICTThe secret changed since you read it (cas did not match)
VAULT_USAGE_REFUSEDAn API call was refused before it was sent. The message says why
VAULT_REQUEST_FAILEDAn API call was sent but failed, for example a timeout

Limits

LimitValue
Secret value64 KiB
Versions kept1 to 100, default 10
List and audit results100 by default, at most 500
API access: allowed hosts per secret20
API access: request body256 KiB
API access: response body1 MiB
API access: timeout15 s by default, 30 s at most

Troubleshooting

You seeDo this
VAULT_ACCESS_DENIED for a member or agentAdd an allow policy for them on that secret, and check no deny matches
An agent is refused although its owner has accessAgents need their own policy (principal_kind: agent)
VAULT_CONFLICTSomeone changed the secret. Check the current version and write again
VAULT_USAGE_REFUSED: no API accessAn owner or admin must turn on API access for the secret
VAULT_USAGE_REFUSED: host not allowedAdd the exact host. Each subdomain is a separate host
body_withheld: trueThe API sent the secret back. Call an endpoint that does not return it
A secret is missing from your listYou need list on it