Vault
Reference
Every vault.* workflow with the permission it needs, error codes, limits and troubleshooting
Workflows
Each workflow acts on your current organization.
| Workflow | Needs | Does |
|---|---|---|
vault.secret.write | write | Store a new version |
vault.secret.read | read | Reveal the value once to the person who asked |
vault.secret.resolve | resolve | Pass the value to a workflow step without showing it |
vault.http.request | use | Call an API with the secret; get the response without it |
vault.secret.usage.set | owner or admin | Turn API access on or off for a secret |
vault.secret.list | list | Secrets you can see, no values |
vault.secret.metadata.get | list | One secret's versions and settings |
vault.secret.delete | delete | Hide versions |
vault.secret.undelete | delete | Restore hidden versions |
vault.secret.destroy | destroy | Erase versions for good |
vault.secret.metadata.delete | destroy | Remove a secret and all its versions |
vault.policy.set / list / delete | admin | Manage policies |
vault.audit.list | admin | Read the audit log |
vault.key.rotate | admin | Rotate the organization's key |
Owners and admins have every permission. See Access policies.
Errors
| Code | Means |
|---|---|
VAULT_ACCESS_DENIED | You don't have permission for this. The audit log shows why |
VAULT_NOT_FOUND | No secret at that path, or no such version |
VAULT_CONFLICT | The secret changed since you read it (cas did not match) |
VAULT_USAGE_REFUSED | An API call was refused before it was sent. The message says why |
VAULT_REQUEST_FAILED | An API call was sent but failed, for example a timeout |
Limits
| Limit | Value |
|---|---|
| Secret value | 64 KiB |
| Versions kept | 1 to 100, default 10 |
| List and audit results | 100 by default, at most 500 |
| API access: allowed hosts per secret | 20 |
| API access: request body | 256 KiB |
| API access: response body | 1 MiB |
| API access: timeout | 15 s by default, 30 s at most |
Troubleshooting
| You see | Do this |
|---|---|
VAULT_ACCESS_DENIED for a member or agent | Add an allow policy for them on that secret, and check no deny matches |
| An agent is refused although its owner has access | Agents need their own policy (principal_kind: agent) |
VAULT_CONFLICT | Someone changed the secret. Check the current version and write again |
VAULT_USAGE_REFUSED: no API access | An owner or admin must turn on API access for the secret |
VAULT_USAGE_REFUSED: host not allowed | Add the exact host. Each subdomain is a separate host |
body_withheld: true | The API sent the secret back. Call an endpoint that does not return it |
| A secret is missing from your list | You need list on it |
